I've discussed this idea on-and-off with a few other people on this list. I finally got around to writing up the program. Feedback is appreciated. -Simson ...
Dear all, does anyone here ever deal with evidence which using PGPDisk? any short way to bypass or maybe access the encrypted disk and read it as unencrypted...
Its real hard process. Even if you know the password. If you dont know the password access data prtk says can broute force to pgp disks. But i never tried...
I have had to work on these, you can get a bootable CD from PGP to decrypt the disk back to its original form but you will need to have 2 clones for evidence...
I already clone the disk, as it is a basic step in forensic, to avoid crashing the evidence disk. regards, Mada "Never Trust an Operating System You don't have...
"Never Trust an Operating System You don't have the Source for..." "Closed Source for device Driver are ILLEGAL and not Ethical... act!" "Isn't it, MS Windows...
Prtk is supposed to work with whole-disk encryption. But it may take a while. I've run it for several weeks on an encrypted laptop disk and gotten no positive...
Hi Mada, I guess you want to decrypt the PGP Whole Disk Encryption. I have no experience with this tool, but from my experience using similar tool from other...
You can check this page for info. http://breach-inv.blogspot.com/2007/05/defeating-whole-disk-encryption-part-1.html ... [Non-text portions of this message...
I was hoping to get help from someone in the group who may have used the above program, frag_find, written by Simson Garfinkel. I've made attempts to contact...
Hi. I didn't get your email. Thanks for sending it here. I didn't get your mail because you are sending it with forged Yahoo ... This frequently happens when...
Simson, I want to thank you. The information you provided did the trick. And thank you for the heads up on my yahoo email account. I definitely have to look...
Bruce, Thanks for the report. Did you have good a good experience with frag_find? Regards, Simson ... [Non-text portions of this message have been removed]...
... Hash: SHA1 Hmmm, the blog post is quite old. A couple of observations, regarding Adam's tools, the python memimage and winlockpwn tool won't work using a...
yes, indeed, I'm screwed, another disk contai .pgd file which another virtual disk encrypted with pgp.;( "Never Trust an Operating System You don't have the...
Hi All, I found this strange behaviour: If I attach an empty NTFS device to Windows, I see that the $Logfile changed, but its metadata don't change (date and...
I think I've seen the same phemonon for other NTFS system files such as $MFT and $BITMAP. Certainly, both of these files change over time but I believe the...
Riley, John H
jriley@...
Mar 23, 2009 3:42 pm
3081
Hi all, I'm glad to announce the Linux Live Forensics distro Caine, made for the netbooks and all usb booting systems: NBCAINE - http://www.caine-live.net/ I...
 I;m using smart eval ver, and trying to do some forensic things on 80Gb dd image, and after I run the the filesystem-SMART-study menu for 10 sec, then...
Personally, I wouldn't run with anything less than 1 GB. I have run SMART on 0.7 GB, but that wasn't particularly enjoyable. Cheers, Ron ... -- Ronald L....
ron@...
Mar 29, 2009 6:00 pm
3084
looks like my attachment file could not send to this mailing list , well here are my lshw from my laptop which I use for running SMART ubuntu-laptop    ...
I already upgrade my RAM into $Gb RAM but still out memory.... Berselancar lebih cepat. Internet Explorer 8 yang dioptimalkan untuk Yahoo! otomatis membuka 2...
Perhaps your SMART issue is better served at the SMART forum? http://www.smartforensics.net/ Cheers! farmerdude http://www.onlineforensictraining.com ...
thanks a lot dude I'm on my way "Never Trust an Operating System You don't have the Source for..." "Closed Source for device Driver are ILLEGAL and not...
All, Based on user feedback, I am happy to announce the release of frag_find version 1.1.1. This program is part of the NPS Bloom Filter package. You can...
Hi all, I developed a new bash script tool Raw2FS, based on TSK: It's possible to resolve the file name starting from the carved file name generated by the...
Does anyone have a good resource, or know anyone that has done some good analysis of the Vista Volume Snapshot Service? I'm looking for information on the...
... I'm sorry for the bad url, this is the right url: http://scripts4cf.sourceforge.net/tools.html and I just developed a new release of Raw2FS, I hope it will...
I need to image a RAID 5 server. Can dcfldd image the logical volumes instead of the individual disks? Are there other tools that can do what I need? Thanks...