Search the web
Sign In
New User? Sign Up
linux_forensics
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Want to share photos of your group with the world? Add a group photo to Flickr.

Best of Y! Groups

   Check them out and nominate your group.
Having problems with message search? Fill out this form to ensure your group is one of the first to be migrated to the new message search system.

Messages

  Messages Help
Advanced
Messages 3092 - 3121 of 3157   Oldest  |  < Older  |  Newer >  |  Newest
Messages: Simplify | Expand   (Group by Topic) Author Sort by Date ^
3092
I need to image a RAID 5 server. Can dcfldd image the logical volumes instead of the individual disks? Are there other tools that can do what I need? Thanks...
basho4n6
Offline Send Email
May 8, 2009
10:20 pm
3093
If you can image the server while it is down, I would image the logical disk (the disk presented to the operating system) using the server (do not pull the...
sploithunter
Offline Send Email
May 9, 2009
4:28 pm
3094
cat /proc/partitions will show all block devices for which there are resident ata, sata, or scsi drivers loaded. ... From: "sploithunter" <church@...> ...
styroteqe
Offline Send Email
May 11, 2009
1:59 pm
3095
This new feature, available for the appliance version, will be automatically integrated with the numerous features PTK has got already. Through...
Michele Zambelli
mizambo
Offline Send Email
May 19, 2009
1:51 pm
3096
Me and Mr. Denis Frati have just finished to implement the latest release of Selective File Dumper, SFDumper for friends;) What's new? Now the software works...
Nanni Bassetti
nannib7013
Offline Send Email
Jun 8, 2009
5:39 pm
3097
Dear Mr Bassetti, I'm an investegator for the Belgium Police in Kortrijk (Belgium). I like to be a beta tester for your new product SFDumper. Please send me a...
Francis Nolf
nolffrancis
Offline Send Email
Jun 10, 2009
12:18 pm
3098
Does anyone here know, how to read a cc skimmer from linux? we have a case in here, we found a credit card skimmer, but we still have problem to read the data...
Mada R Perdhana
mrp_bpp
Offline Send Email
Jul 3, 2009
1:46 am
3099
Hi I have the same problem and would also like some advice. The device in my possession has no markings or model number. Any help will do Beaunard Grobler ...
CCIU
ccu@...
Send Email
Jul 3, 2009
5:31 am
3100
Are you sure that the devices are self contained models? Some of the devices I have seen are designed to connect either to a handheld device (pocket pc) or...
Patrick
mingthemercil
Offline Send Email
Jul 3, 2009
11:44 am
3101
frag_find is a program that searches the blocks of disk IMAGE for one or more TARGET files. It does this by checking the SHA1 hash of every block of the target...
Simson Garfinkel
simsongarfinkel
Offline Send Email
Jul 5, 2009
4:12 am
3102
Can you send a picture? Also what types of cables you are using to connect to your system. I am not sure about finding a reliable device driver for those...
mark mendelson
arduousbyte
Offline Send Email
Jul 5, 2009
5:26 am
3103
Hi Everyone, I have found evidence of credit card fraud in Windows Vista system restore volumes with a grep expression. The suspect appears to have been...
Lehr, John
slopd4256
Offline Send Email
Jul 13, 2009
8:45 pm
3104
Well, from within Windows, programatically speaking, the Shadow Volumes just map back to the physical volume. Meaning, if you have ten HarddiskShadowCopyXX...
swinginscott
Offline Send Email
Jul 14, 2009
12:03 pm
3105
... As far as I know you should operate on the original disk (write-blocked) from a Windows Vista OS. By using vssadmin.exe and mkink.exe you can have access...
fpi
francesco.pi...
Offline Send Email
Jul 14, 2009
12:19 pm
3106
You may find this resource useful. http://sansforensics.wordpress.com/2008/10/10/shadow-forensics/ Jon. ... From: swinginscott <swinginscott@...> ...
Echo6
echo6_uk
Offline Send Email
Jul 14, 2009
12:55 pm
3107
Thank you for your replies. Looking at the shadow volumes with a hex viewer, the volumes look like databases as Scott suggests from his review of the API....
Lehr, John
slopd4256
Offline Send Email
Jul 14, 2009
6:29 pm
3108
I believe you can do the restoration with the Windows 7 RC1. The RC has a 180 day eval license. ... From: "Lehr, John" <jlehr@...> To:...
styroteqe
Offline Send Email
Jul 14, 2009
7:11 pm
3109
configure: ***************************************** configure: AFFLIB 3.3.6 configuration configure: Amazon S3 Support: no configure: LZMA Compression: yes...
Stuart Bird
e_tective
Offline Send Email
Jul 22, 2009
6:42 am
3110
Hi. What platform are you compiling on, and do you have SHA256? You might want to compare the compile environment of the test program in the log file with the...
Simson Garfinkel
simsongarfinkel
Offline Send Email
Jul 22, 2009
10:37 am
3111
Hi Simson I am compiling on Slackware 12.2 (32 bit). I couldn't find a specific package for SHA-256 although I did install a package called mhash which I was...
Stuart Bird
e_tective
Offline Send Email
Jul 22, 2009
1:24 pm
3112
Fellow Professionals, This is the last week to register for the Digital Forensics Seminar. HiTek Digital Forensics is holding a one day seminar on July 29,...
Dennis Leslie
drleslie46
Offline Send Email
Jul 22, 2009
1:39 pm
3113
Does anyone know of any online forensic seminars to earn some CPE. I need to get a few hours in before the end of the year without spending too much money to...
Bob Kardell
bobkardell
Offline Send Email
Jul 22, 2009
2:06 pm
3114
Stu/Simson, Doesn't something like OpenSSL or libcrypto provide these? Jon Sent from my iPhone ... [Non-text portions of this message have been removed]...
Echo Six
echo6_uk
Offline Send Email
Jul 22, 2009
3:31 pm
3115
That's your problem. You need to install the current version of OpenSSL. ... [Non-text portions of this message have been removed]...
Simson Garfinkel
simsongarfinkel
Offline Send Email
Jul 22, 2009
3:40 pm
3116
SHA-256 is not present in all versions of OpenSSL, which is why the configure script checks for it. My hunch is that the system below has multiple copies of...
Simson Garfinkel
simsongarfinkel
Offline Send Email
Jul 22, 2009
3:40 pm
3117
Thanks Jon, a newer openssl package sorted the issue. Stu ________________________________ From: Echo Six <echo6_uk@...> To:...
Stuart Bird
e_tective
Offline Send Email
Jul 22, 2009
3:50 pm
3118
Simson Now sorted thanks, it was an outdated openssl package at fault. Stu ________________________________ From: Simson Garfinkel <simsong@...> To:...
Stuart Bird
e_tective
Offline Send Email
Jul 22, 2009
3:54 pm
3119
Thanks. I should add this to the configure program. ... [Non-text portions of this message have been removed]...
Simson Garfinkel
simsongarfinkel
Offline Send Email
Jul 22, 2009
4:34 pm
3120
DFLabs is proud to announce the new "video" section on the website dedicated to the PTK project. Thanks to the new section features that have already...
Michele Zambelli
mizambo
Offline Send Email
Jul 29, 2009
8:48 am
3121
Hi All, I'm an experienced linux user/developer/sysadmin and am looking to work up a bit of knowledge (and experience) with regards to performing data recovery...
skyphyr@...
skyphyr...
Offline Send Email
Aug 23, 2009
10:53 am
Messages 3092 - 3121 of 3157   Oldest  |  < Older  |  Newer >  |  Newest
Advanced
Add to My Yahoo!      XML What's This?

Copyright © 2009 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines - Help