Search the web
Sign In
New User? Sign Up
linux_forensics
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Want your group to be featured on the Yahoo! Groups website? Add a group photo to Flickr.

Best of Y! Groups

   Check them out and nominate your group.
Having problems with message search? Fill out this form to ensure your group is one of the first to be migrated to the new message search system.

Messages

  Messages Help
Advanced
Messages 2971 - 3000 of 3157   Oldest  |  < Older  |  Newer >  |  Newest
Messages: Simplify | Expand   (Group by Topic) Author Sort by Date ^
2971
Does anybody know how to acquire memory from a MacOS machine running MacOS 10.5? /dev/mem is gone......
Simson Garfinkel
simsongarfinkel
Offline Send Email
Oct 6, 2008
1:50 am
2972
Simson You could try hibernating it to create a 'sleepimage' file making use of Mac's 'Safe Sleep' function then image it as normal. There is a short...
Stuart Bird
e_tective
Offline Send Email
Oct 7, 2008
7:38 am
2973
... Hash: SHA1 http://www.osxbook.com/book/bonus/chapter8/kma Or you could acquire memory over firewire ! Jon. ... Version: GnuPG v1.4.6 (GNU/Linux) Comment:...
echo6
echo6_uk
Offline Send Email
Oct 7, 2008
1:18 pm
2974
That's an interesting idea! So you are recommending this procedure: 1. Just close the lid of the laptop. 2. Wait a few minutes 3. Pop the battery. 4. Boot the...
Simson Garfinkel
simsongarfinkel
Offline Send Email
Oct 7, 2008
5:43 pm
2975
That's an interesting idea! So you are recommending this procedure: 1. Just close the lid of the laptop. 2. Wait a few minutes 3. Pop the battery. 4. Boot the...
Simson Garfinkel
simsongarfinkel
Offline Send Email
Oct 7, 2008
5:43 pm
2976
Simson "Recommending" is probably not the phrase I would have chosen, I merely offer it as a suggested workaround if you have no other options : ) and I would...
Stuart Bird
e_tective
Offline Send Email
Oct 7, 2008
7:04 pm
2977
Simson I found a further article here: http://brockwoolf.com/safe-sleep-guide-for-mac-os-x It would appear that 'Safe Sleep' and 'Secure Virtual Memory' do not...
Stuart Bird
e_tective
Offline Send Email
Oct 7, 2008
7:36 pm
2978
... I've never gotten the firewire trick to work. Have you gotten it to work? These days I can't even find firewire iPods......
Simson Garfinkel
simsongarfinkel
Offline Send Email
Oct 7, 2008
10:04 pm
2979
I am happy to announce the following: 1. /private/var/vm/sleepimage is in fact a copy of the Macintosh Laptop's memory, as it was when the mac went to sleep...
Simson Garfinkel
simsongarfinkel
Offline Send Email
Oct 7, 2008
10:53 pm
2980
... Hash: SHA1 Simson, Yes, I have got it working. More reliably on *nix target systems than Windows. (Windows Forensic Analysis by Harlan Carvey) Ideally use...
echo6
echo6_uk
Offline Send Email
Oct 7, 2008
10:54 pm
2981
... Awesome. Which programs do we use? ... Thanks. I'll give it a try and report back if you can fill me in on what to use......
Simson Garfinkel
simsongarfinkel
Offline Send Email
Oct 8, 2008
2:29 am
2982
-- Carthago delenda est! [Non-text portions of this message have been removed]...
Michael Harrington
chimpinlinux
Offline Send Email
Oct 8, 2008
7:01 pm
2983
Sorry for the last post. -- Carthago delenda est! [Non-text portions of this message have been removed]...
Michael Harrington
chimpinlinux
Offline Send Email
Oct 8, 2008
7:02 pm
2984
Can anyone advise on how I compare the contents of folders using 'md5deep'. I have four folders each of which are the contents of restored dat tapes. I suspect...
Stuart Bird
e_tective
Offline Send Email
Oct 15, 2008
3:50 pm
2985
Stuart - I haven't verified this method but shooting from the hip, Can you tar the 4 folders and then use md5 on the resulting tarballs? This should tell you...
Brad Tumy
bradtumy
Offline Send Email
Oct 15, 2008
4:00 pm
2986
To identify missing or modified files: md5deep -r -x [hash list file] -n [target directory] To identify added or modified files: md5deep -r -x [hash list file]...
kelly bwc
kelly.bwc@...
Send Email
Oct 15, 2008
6:05 pm
2987
You can use FTimes to accomplish your task as described in the steps below. This approach requires FTimes 3.8.0 or higher and ftimes-xformer 1.12 or higher....
andy.bair
Offline Send Email
Oct 16, 2008
7:08 am
2988
... This procedure may not work. If the computer, for whatever reason, decides to tar the files in a different order, even identical files might create...
Jesse Kornblum
jessekornblum
Online Now Send Email
Oct 16, 2008
11:23 am
2989
... These command lines are exactly right, thank you! ... Yes. I wrote hashdeep so that you wouldn't need two command lines to test the integrity of a...
Jesse Kornblum
jessekornblum
Online Now Send Email
Oct 16, 2008
11:26 am
2990
Thanks very much to all who answered, some very useful and detailed replies. Stu ... From: Jesse Kornblum <research@...> To:...
Stuart Bird
e_tective
Offline Send Email
Oct 16, 2008
11:57 am
2991
Jesse - I didn't even think about that with tar. Thanks for the feedback on that. BTW ... just found foremost this week and have used it already. Thanks for...
Brad Tumy
bradtumy
Offline Send Email
Oct 16, 2008
11:59 am
2992
Hi, I'm looking for a PyFlag VMWare appliance, but couldn`t find it, yet. Could anyone help me with this ? Thanks in advance -- Tony Rodrigues, CISSP, CFCP ...
Tony Rodrigues
fotografo_to...
Offline Send Email
Oct 21, 2008
12:36 am
2993
... Hash: SHA1 I don not think there is one! At least not that I am aware of. I suppose you could always suggest this to Michael Cohen the author. Jon. ... ...
echo6
echo6_uk
Offline Send Email
Oct 21, 2008
7:36 pm
2994
Thank you, Jon. I was afraid of that. Well, I will wait more one or two days, and if nobody has a clue, I will proceed and ask him. Thanks, Tony ... -- Tony...
Tony Rodrigues
fotografo_to...
Offline Send Email
Oct 21, 2008
11:17 pm
2995
Good morning, I have what should be an image of a reconstructed RAID 1+0 array from a freebsd system. RAID Reconstructor "blessed" one particular configuration...
David Kovar
dkovar
Online Now Send Email
Nov 1, 2008
10:19 pm
2996
Greetings. Are there any good log file analysis tools that people are using for forensic or incident response? I have heard that some people are using...
Simson Garfinkel
simsongarfinkel
Offline Send Email
Nov 3, 2008
2:01 am
2997
I've run some trials with Sawmill. It is commercial, flexible and it natively covers a large number of log formats. http://www.sawmill.net/index.html. ...
Brewis, Mark
mark.brewis@...
Send Email
Nov 3, 2008
9:25 am
2998
however Win32, but my logparser of choice is the free Microsoft LogParser 2.2 ...
Mark Stam
stamblogs
Offline Send Email
Nov 3, 2008
11:05 am
2999
Hi Simson, Since you sent this to the Linux Forensics group I'm presuming you're looking for A) tools to analyze log files common to the Linux operating system...
farmerdude
farmerduderl
Offline Send Email
Nov 7, 2008
1:23 am
3000
I'm not familiar with Delve or grokevt. Can you provide URLs? In general, most of the programs I've seen do parsing, but do not do detailed correlation,...
Simson Garfinkel
simsongarfinkel
Offline Send Email
Nov 7, 2008
5:14 am
Messages 2971 - 3000 of 3157   Oldest  |  < Older  |  Newer >  |  Newest
Advanced
Add to My Yahoo!      XML What's This?

Copyright © 2009 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines - Help