Search the web
Sign In
New User? Sign Up
linux_forensics
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Hear how Yahoo! Groups has changed the lives of others. Take me there.

Best of Y! Groups

   Check them out and nominate your group.
Having problems with message search? Fill out this form to ensure your group is one of the first to be migrated to the new message search system.

Messages

  Messages Help
Advanced
Messages 2950 - 2979 of 3157   Oldest  |  < Older  |  Newer >  |  Newest
Messages: Simplify | Expand   (Group by Topic) Author Sort by Date ^
2950
Version 3.65 is released www.linuxleo.com See the changelog for details. Barry bgrundy@......
Grundy, Barry J. (HQ-...
grundy_b
Offline Send Email
Sep 5, 2008
2:40 am
2951
Thank you for all your hard work. ... Version 3.65 is released www.linuxleo.com See the changelog for details. Barry bgrundy@... (...
Luis Salazar
Luis.Salazar@...
Send Email
Sep 5, 2008
3:23 pm
2952
On Thu, 4 Sep 2008 21:40:41 -0500 ... Thanks, Barry - excellent document, as always. :-) -RW...
Robby Workman
robw810
Offline Send Email
Sep 5, 2008
3:38 pm
2953
Very very much appreciated! Thanks Barry! Ken Pryor ... [Non-text portions of this message have been removed]...
Ken Pryor
kdpryor
Offline Send Email
Sep 5, 2008
3:39 pm
2954
... Thanks, Barry. All your effort is very much appreciated. -- Neil Marsh, CFCE, WA PI #2840 Marsh Computer Forensics, LLC PO Box 246 Chehalis WA 98532-0246...
Neil Marsh
neil123chehpd
Offline Send Email
Sep 5, 2008
4:57 pm
2955
Thanks Barry....that's good! ;) ... Dott. Nanni Bassetti Consulente Information Security http://www.nannibassetti.com/ Cell. +39-3476587097 CFI -...
Nanni Bassetti
nannib7013
Offline Send Email
Sep 5, 2008
7:54 pm
2956
Barry just to add to the list of thankyou's. your hard work is much appreciated here too. tip o' the hat to you. Kern [Non-text portions of this message have...
kern
kern.uk@...
Send Email
Sep 7, 2008
9:52 am
2957
All, I would appreciate some help with a matter. I am looking to run a recursive hash of all files within a folder on a Program Files folder on an XP machine...
Garret Rain
attic_storm2000
Offline Send Email
Sep 13, 2008
10:25 am
2958
md5deep Simply mount the NTFS partition from each drive. Run md5deep recursively on the first folder and pipe to a file. Then run it against the second...
Jacques B.
jboucher_work
Offline Send Email
Sep 13, 2008
2:36 pm
2959
You might want to try hashdeep, part of the md5deep suite, http://md5deep.sf.net/ In particular, the audit mode may be exactly what you're looking for. To...
Jesse Kornblum
jessekornblum
Offline Send Email
Sep 14, 2008
4:47 pm
2960
I have a Perl script I use for just such a purpose.  It is really set up to run on Windows to capture extra information, but can be used on Linux or Mac as...
Bob Kardell
bobkardell
Offline Send Email
Sep 14, 2008
6:09 pm
2961
Bob, I would be interested in a copy of your Perl script if you would be so kind. Ken Pryor ... [Non-text portions of this message have been removed]...
Ken Pryor
kdpryor
Offline Send Email
Sep 14, 2008
6:28 pm
2962
http://bobkardell.tripod.com/ Please test them. Thanks, Bob ... From: Ken Pryor <kdpryor@...> To: linux_forensics@yahoogroups.com Sent: Sunday, September...
Bob Kardell
bobkardell
Offline Send Email
Sep 15, 2008
3:35 am
2963
Hi Hopefully just a quickie for someone :) Can anyone tell me how to make 'xxd' display decimal offsets rather than hex. I have had a hunt around the man pages...
Stuart Bird
e_tective
Offline Send Email
Sep 17, 2008
7:48 am
2964
While I haven't really tried it, so forgive me if it doesn't work. Offhand, it seems like you could script it to output just like you want. Just have xxd...
swinginscott
Offline Send Email
Sep 17, 2008
6:51 pm
2965
... You can use FTimes to accomplish your task as follows: 1) Take a snapshot of the issue PC files: C:\> ftimes --mapauto none+hashes -l 6 "C:\Program Files"...
snortboy2112
Offline Send Email
Sep 17, 2008
8:24 pm
2966
Garret, You can use FTimes to accomplish your task as follows: 1) Take a snapshot of the issue PC files: C:\> ftimes --mapauto none+hashes -l 6 "C:\Program...
andy.bair
Offline Send Email
Sep 17, 2008
9:38 pm
2967
... Hash: SHA1 Hi Stu, Doesn't look as though hexdump can either. From the gui though you can set khexedit to use offset in hex or decimal. Jon. ... Version:...
echo6
echo6_uk
Offline Send Email
Sep 21, 2008
7:11 pm
2968
... Hmm ... maybe I've missed a post, or have a different version ... My version of hexdump shows decimal. Did I miss something? Cheers! farmerdude ...
farmerdude
farmerduderl
Offline Send Email
Sep 26, 2008
1:22 am
2969
farmerdude, As can be seen below the offsets are definitely in hex. I am using version 1.10 27oct98 which on the face of it does seem quite old. I'll see if...
Stuart Bird
e_tective
Offline Send Email
Sep 26, 2008
10:31 am
2970
... Hash: SHA1 Stu, that's the version I have, owned by vim-common 1:7.1-138+1ubuntu3 under Ubuntu 8.10.1, which is the most recent version. Thomas, you got...
echo6
echo6_uk
Offline Send Email
Sep 26, 2008
4:14 pm
2971
Does anybody know how to acquire memory from a MacOS machine running MacOS 10.5? /dev/mem is gone......
Simson Garfinkel
simsongarfinkel
Offline Send Email
Oct 6, 2008
1:50 am
2972
Simson You could try hibernating it to create a 'sleepimage' file making use of Mac's 'Safe Sleep' function then image it as normal. There is a short...
Stuart Bird
e_tective
Offline Send Email
Oct 7, 2008
7:38 am
2973
... Hash: SHA1 http://www.osxbook.com/book/bonus/chapter8/kma Or you could acquire memory over firewire ! Jon. ... Version: GnuPG v1.4.6 (GNU/Linux) Comment:...
echo6
echo6_uk
Offline Send Email
Oct 7, 2008
1:18 pm
2974
That's an interesting idea! So you are recommending this procedure: 1. Just close the lid of the laptop. 2. Wait a few minutes 3. Pop the battery. 4. Boot the...
Simson Garfinkel
simsongarfinkel
Offline Send Email
Oct 7, 2008
5:43 pm
2975
That's an interesting idea! So you are recommending this procedure: 1. Just close the lid of the laptop. 2. Wait a few minutes 3. Pop the battery. 4. Boot the...
Simson Garfinkel
simsongarfinkel
Offline Send Email
Oct 7, 2008
5:43 pm
2976
Simson "Recommending" is probably not the phrase I would have chosen, I merely offer it as a suggested workaround if you have no other options : ) and I would...
Stuart Bird
e_tective
Offline Send Email
Oct 7, 2008
7:04 pm
2977
Simson I found a further article here: http://brockwoolf.com/safe-sleep-guide-for-mac-os-x It would appear that 'Safe Sleep' and 'Secure Virtual Memory' do not...
Stuart Bird
e_tective
Offline Send Email
Oct 7, 2008
7:36 pm
2978
... I've never gotten the firewire trick to work. Have you gotten it to work? These days I can't even find firewire iPods......
Simson Garfinkel
simsongarfinkel
Offline Send Email
Oct 7, 2008
10:04 pm
2979
I am happy to announce the following: 1. /private/var/vm/sleepimage is in fact a copy of the Macintosh Laptop's memory, as it was when the mac went to sleep...
Simson Garfinkel
simsongarfinkel
Offline Send Email
Oct 7, 2008
10:53 pm
Messages 2950 - 2979 of 3157   Oldest  |  < Older  |  Newer >  |  Newest
Advanced
Add to My Yahoo!      XML What's This?

Copyright © 2009 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines - Help