Search the web
Sign In
New User? Sign Up
linux_forensics
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Want your group to be featured on the Yahoo! Groups website? Add a group photo to Flickr.

Best of Y! Groups

   Check them out and nominate your group.
Having problems with message search? Fill out this form to ensure your group is one of the first to be migrated to the new message search system.

Messages

  Messages Help
Advanced
Messages 2899 - 2928 of 3157   Oldest  |  < Older  |  Newer >  |  Newest
Messages: Simplify | Expand   (Group by Topic) Author Sort by Date ^
2899
I'm looking for a good tool to hash a complete disk (md5). I need to check and report the integrity of a disk before I make a forensic image of it. Of course,...
Mark
stamblogs
Offline Send Email
Jul 8, 2008
7:22 pm
2900
Hi Mark, SMART by ASR Data has an excellent authentication engine. It's quite robust and is available in a clean, easy-to-navigate graphical user interface. ...
farmerdude
farmerduderl
Offline Send Email
Jul 8, 2008
7:30 pm
2901
... We wrap the imaging and md5-ing all into a single ddcfld command: dcfldd if=$source_drive of=$image_file bs=256b hash=md5 \ hashlog=$md5_file sizeprobe=if...
Gary Funck
garyfunck
Offline Send Email
Jul 8, 2008
8:01 pm
2902
I'm biased, but md5deep (http://md5deep.sf.net/) has a nice progress indicator: $ md5deep -e /dev/sdc Lots of other bells and whistles too! cheers, ... -- ...
Jesse Kornblum
jessekornblum
Online Now Send Email
Jul 9, 2008
1:30 am
2903
Hi All, (Just posted this to Forensic Focus this morning) Has anyone done any work on UTF-8 encoded data using TSK or on linux in general? The file system...
Daniel, Adam (AU - Sy...
addaniel@...
Send Email
Jul 9, 2008
8:55 am
2904
Are you looking for all UTF-8 strings or just English UTF-8 strings? An overall problem of doing strings extraction for all of Unicode is that most byte...
Brian Carrier
bdcarrier
Offline Send Email
Jul 9, 2008
3:16 pm
2905
Hi Jesse, I use md5deep since a while and I really like this tool. I now realize I can also use it to hash complete drives with it. Thanks, Mark ... like to ...
Mark
stamblogs
Offline Send Email
Jul 10, 2008
1:34 pm
2906
When I boot with Helix and I connect a (USB) disk, I see this message in the console: ... sda: Write protect is off ... which is a little confusing for me, as...
Mark
stamblogs
Offline Send Email
Jul 10, 2008
11:26 pm
2907
Mark, The "write protect is off" message you are getting does not refer to the mount options for any filesystem on sda. Check with the "mount" command by...
Grundy, Barry J. (HQ-...
grundy_b
Offline Send Email
Jul 11, 2008
12:11 am
2908
... But with Helix, can you really trust this? Given the author's indignation and disdain for constructive criticism on an blatant flaw with the product, I'd...
The Dog's Bollix
ISXPRO
Offline Send Email
Jul 11, 2008
1:45 am
2909
This thread reminded me of something that I was going to ask about that relates to the previous thread regarding unintentional writes to a reiserfs partition...
Gary Funck
garyfunck
Offline Send Email
Jul 11, 2008
2:42 am
2910
Thanks for your mail ... I think this can easily be verified now: boot with Helix CD connect a disk to an open USB port use md5deep to hash the contents of the...
Mark
stamblogs
Offline Send Email
Jul 11, 2008
6:51 am
2911
I recently had a few issues with helix when i was trying to acquire an IDE disk attached by a Magic Bridge USB/IDE connector. Never really got to the bottom of...
michael
barryradish1958
Offline Send Email
Jul 11, 2008
6:59 am
2912
... I can. Yes. We trust what we test. Is there anything you trust that you haven't tested? On the flip side, is there anything you've tested (and passed)...
Grundy, Barry J. (HQ-...
grundy_b
Offline Send Email
Jul 11, 2008
1:31 pm
2913
Barry, Excellent point. Cliff ... From: Grundy, Barry J. (HQ-WIM51) <bgrundy@...> Subject: RE: [linux_forensics] Helix: Write Protect is off To:...
The Dog's Bollix
ISXPRO
Offline Send Email
Jul 11, 2008
1:35 pm
2914
... Actually, the definition of trusting something is putting the thing in a position where, if it doesn't work if you expect it to work, it will hurt you....
Simson Garfinkel
simsongarfinkel
Offline Send Email
Jul 11, 2008
3:39 pm
2915
You Wrote: Actually, the definition of trusting something is putting the thing in a position where, if it doesn't work if you expect it to work, it will hurt...
Grundy, Barry J. (HQ-...
grundy_b
Offline Send Email
Jul 11, 2008
3:58 pm
2916
Howdy - I'd like to invite members of this list to evaluate a Linux tool we've been developing that has numerous practical applications to data forensics. ...
asrdata
Offline Send Email
Jul 11, 2008
5:34 pm
2917
I am very interested in this. I'll download and try it out. Thanks! Ken Pryor ... [Non-text portions of this message have been removed]...
Ken Pryor
kdpryor
Offline Send Email
Jul 11, 2008
6:17 pm
2918
Greetings, This a bit harsh, I think. Perhaps you could get the point across a bit more diplomatically? -David ... [Non-text portions of this message have been...
David Kovar
dkovar
Online Now Send Email
Jul 12, 2008
3:39 pm
2919
... haha... you need to look at the previous thread to see the non diplomatic way in which the helix author made a false claim about his tool when it was...
Harry Duncan
usr.src.linux@...
Send Email
Jul 12, 2008
3:45 pm
2920
Harry, Cliff et al, Before this starts off another flame war, can we please put this petty squabbling to bed. The point was made during the previous thread...
Jim Gordon
jimg1893
Offline Send Email
Jul 12, 2008
5:29 pm
2921
What flame war? A recommendation was made. The recommendation was vilified. When asked for proof the recommendation was false, silence ensued. When the...
The Dog's Bollix
ISXPRO
Offline Send Email
Jul 12, 2008
11:31 pm
2922
Hello All, I just wanted to see if anyone has an SOP for processing Linux LVM/LVM2 or BSD Vinum volumes? I am also looking for the best approach when...
Tim Fowler
timothy.m.fowler@...
Send Email
Jul 14, 2008
3:26 pm
2923
... Rumor has it that Slackware is somewhat popular as a forensics base, and I'd like to think that I'm somewhat familiar with Slackware, so maybe I can help...
Robby Workman
robw810
Offline Send Email
Jul 15, 2008
7:55 am
2924
Hi Has mounted several split DD images on a Windows XP SP2 platform successfully although it sometimes closed unexpectedly on a couple of occasions during the...
Jason Wright
jasonatbrisbane
Offline Send Email
Jul 15, 2008
11:14 am
2925
Hi Jason - The Linux version does the physical disk and vmdk creation, the Windows version presently does not. At some future point, we may provide a physical...
ASR Data
asrdata
Offline Send Email
Jul 15, 2008
2:33 pm
2926
Greetings, Version 12 of the FCCU GNU/Linux Forensic Boot CD was released recently. I'm curious if anyone has any experience with it and how it compares with...
David Kovar
dkovar
Online Now Send Email
Jul 15, 2008
3:48 pm
2927
David, I have some posts, in my blog, comparing them. The posts are in portuguese, but you can use a web translator. []s -- Tony Rodrigues, CISSP Forense...
Tony Rodrigues
fotografo_to...
Offline Send Email
Jul 15, 2008
6:23 pm
2928
I want to use an older PC with Debian to make forensic images of harddisks. To be sure no data will be written to the drives I want to image (write...
Mark
stamblogs
Offline Send Email
Jul 15, 2008
6:37 pm
Messages 2899 - 2928 of 3157   Oldest  |  < Older  |  Newer >  |  Newest
Advanced
Add to My Yahoo!      XML What's This?

Copyright © 2009 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines - Help