Search the web
Sign In
New User? Sign Up
linux_forensics
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Real people. Real stories. See how Yahoo! Groups impacts members worldwide.

Best of Y! Groups

   Check them out and nominate your group.
Having problems with message search? Fill out this form to ensure your group is one of the first to be migrated to the new message search system.

Messages

  Messages Help
Advanced
Messages 3088 - 3117 of 3157   Oldest  |  < Older  |  Newer >  |  Newest
Messages: Simplify | Expand   (Group by Topic) Author Sort by Date ^
3088
All, Based on user feedback, I am happy to announce the release of frag_find version 1.1.1. This program is part of the NPS Bloom Filter package. You can...
Simson Garfinkel
simsongarfinkel
Offline Send Email
Apr 12, 2009
5:36 pm
3089
Hi all, I developed a new bash script tool Raw2FS, based on TSK: It's possible to resolve the file name starting from the carved file name generated by the...
Nanni Bassetti
nannib7013
Offline Send Email
Apr 20, 2009
8:52 am
3090
Does anyone have a good resource, or know anyone that has done some good analysis of the Vista Volume Snapshot Service? I'm looking for information on the...
swinginscott
Offline Send Email
Apr 20, 2009
2:57 pm
3091
... I'm sorry for the bad url, this is the right url: http://scripts4cf.sourceforge.net/tools.html and I just developed a new release of Raw2FS, I hope it will...
nannib7013
Offline Send Email
Apr 22, 2009
11:34 pm
3092
I need to image a RAID 5 server. Can dcfldd image the logical volumes instead of the individual disks? Are there other tools that can do what I need? Thanks...
basho4n6
Offline Send Email
May 8, 2009
10:20 pm
3093
If you can image the server while it is down, I would image the logical disk (the disk presented to the operating system) using the server (do not pull the...
sploithunter
Offline Send Email
May 9, 2009
4:28 pm
3094
cat /proc/partitions will show all block devices for which there are resident ata, sata, or scsi drivers loaded. ... From: "sploithunter" <church@...> ...
styroteqe
Offline Send Email
May 11, 2009
1:59 pm
3095
This new feature, available for the appliance version, will be automatically integrated with the numerous features PTK has got already. Through...
Michele Zambelli
mizambo
Offline Send Email
May 19, 2009
1:51 pm
3096
Me and Mr. Denis Frati have just finished to implement the latest release of Selective File Dumper, SFDumper for friends;) What's new? Now the software works...
Nanni Bassetti
nannib7013
Offline Send Email
Jun 8, 2009
5:39 pm
3097
Dear Mr Bassetti, I'm an investegator for the Belgium Police in Kortrijk (Belgium). I like to be a beta tester for your new product SFDumper. Please send me a...
Francis Nolf
nolffrancis
Offline Send Email
Jun 10, 2009
12:18 pm
3098
Does anyone here know, how to read a cc skimmer from linux? we have a case in here, we found a credit card skimmer, but we still have problem to read the data...
Mada R Perdhana
mrp_bpp
Offline Send Email
Jul 3, 2009
1:46 am
3099
Hi I have the same problem and would also like some advice. The device in my possession has no markings or model number. Any help will do Beaunard Grobler ...
CCIU
ccu@...
Send Email
Jul 3, 2009
5:31 am
3100
Are you sure that the devices are self contained models? Some of the devices I have seen are designed to connect either to a handheld device (pocket pc) or...
Patrick
mingthemercil
Offline Send Email
Jul 3, 2009
11:44 am
3101
frag_find is a program that searches the blocks of disk IMAGE for one or more TARGET files. It does this by checking the SHA1 hash of every block of the target...
Simson Garfinkel
simsongarfinkel
Offline Send Email
Jul 5, 2009
4:12 am
3102
Can you send a picture? Also what types of cables you are using to connect to your system. I am not sure about finding a reliable device driver for those...
mark mendelson
arduousbyte
Offline Send Email
Jul 5, 2009
5:26 am
3103
Hi Everyone, I have found evidence of credit card fraud in Windows Vista system restore volumes with a grep expression. The suspect appears to have been...
Lehr, John
slopd4256
Offline Send Email
Jul 13, 2009
8:45 pm
3104
Well, from within Windows, programatically speaking, the Shadow Volumes just map back to the physical volume. Meaning, if you have ten HarddiskShadowCopyXX...
swinginscott
Offline Send Email
Jul 14, 2009
12:03 pm
3105
... As far as I know you should operate on the original disk (write-blocked) from a Windows Vista OS. By using vssadmin.exe and mkink.exe you can have access...
fpi
francesco.pi...
Offline Send Email
Jul 14, 2009
12:19 pm
3106
You may find this resource useful. http://sansforensics.wordpress.com/2008/10/10/shadow-forensics/ Jon. ... From: swinginscott <swinginscott@...> ...
Echo6
echo6_uk
Offline Send Email
Jul 14, 2009
12:55 pm
3107
Thank you for your replies. Looking at the shadow volumes with a hex viewer, the volumes look like databases as Scott suggests from his review of the API....
Lehr, John
slopd4256
Offline Send Email
Jul 14, 2009
6:29 pm
3108
I believe you can do the restoration with the Windows 7 RC1. The RC has a 180 day eval license. ... From: "Lehr, John" <jlehr@...> To:...
styroteqe
Offline Send Email
Jul 14, 2009
7:11 pm
3109
configure: ***************************************** configure: AFFLIB 3.3.6 configuration configure: Amazon S3 Support: no configure: LZMA Compression: yes...
Stuart Bird
e_tective
Offline Send Email
Jul 22, 2009
6:42 am
3110
Hi. What platform are you compiling on, and do you have SHA256? You might want to compare the compile environment of the test program in the log file with the...
Simson Garfinkel
simsongarfinkel
Offline Send Email
Jul 22, 2009
10:37 am
3111
Hi Simson I am compiling on Slackware 12.2 (32 bit). I couldn't find a specific package for SHA-256 although I did install a package called mhash which I was...
Stuart Bird
e_tective
Offline Send Email
Jul 22, 2009
1:24 pm
3112
Fellow Professionals, This is the last week to register for the Digital Forensics Seminar. HiTek Digital Forensics is holding a one day seminar on July 29,...
Dennis Leslie
drleslie46
Offline Send Email
Jul 22, 2009
1:39 pm
3113
Does anyone know of any online forensic seminars to earn some CPE. I need to get a few hours in before the end of the year without spending too much money to...
Bob Kardell
bobkardell
Offline Send Email
Jul 22, 2009
2:06 pm
3114
Stu/Simson, Doesn't something like OpenSSL or libcrypto provide these? Jon Sent from my iPhone ... [Non-text portions of this message have been removed]...
Echo Six
echo6_uk
Offline Send Email
Jul 22, 2009
3:31 pm
3115
That's your problem. You need to install the current version of OpenSSL. ... [Non-text portions of this message have been removed]...
Simson Garfinkel
simsongarfinkel
Offline Send Email
Jul 22, 2009
3:40 pm
3116
SHA-256 is not present in all versions of OpenSSL, which is why the configure script checks for it. My hunch is that the system below has multiple copies of...
Simson Garfinkel
simsongarfinkel
Offline Send Email
Jul 22, 2009
3:40 pm
3117
Thanks Jon, a newer openssl package sorted the issue. Stu ________________________________ From: Echo Six <echo6_uk@...> To:...
Stuart Bird
e_tective
Offline Send Email
Jul 22, 2009
3:50 pm
Messages 3088 - 3117 of 3157   Oldest  |  < Older  |  Newer >  |  Newest
Advanced
Add to My Yahoo!      XML What's This?

Copyright © 2009 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines - Help