Search the web
Sign In
New User? Sign Up
linux_forensics
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Real people. Real stories. See how Yahoo! Groups impacts members worldwide.

Best of Y! Groups

   Check them out and nominate your group.
Having problems with message search? Fill out this form to ensure your group is one of the first to be migrated to the new message search system.

Messages

  Messages Help
Advanced
Messages 3146 - 3175 of 3175   Newest  |  < Newer  |  Older >  |  Oldest
Messages: Simplify | Expand   (Group by Topic) Author Sort by Date v
3175
... Hi, don't forget the excellent perl module Parse::Win32Registry. http://search.cpan.org/~jmacfarla/Parse-Win32Registry-0.51/lib/Parse/Win32Registry.pm ...
Christophe Monniez
d_fence_242
Offline Send Email
Dec 29, 2009
4:25 pm
3174
Thanks to everyone who answered. I have updated the Windows Registry page on the forensicswiki to include all of the information that I was given. ...
Simson Garfinkel
simsongarfinkel
Offline Send Email
Dec 27, 2009
7:31 am
3173
... Simson, I do not know of such an MS Registry decoder, but I suspect that, if anyone knew of such a decoder, it would likely be a participant on the Windows...
Paul D. Bain
pauldbain
Offline Send Email
Dec 22, 2009
10:35 pm
3172
... Take a look at Brian Carrier's site under unix tools and search for "registry" http://www.opensourceforensics.org/tools/unix.html HTH, -Enda....
Enda Cronnolly
endacronnolly
Offline Send Email
Dec 22, 2009
10:29 pm
3171
Hi Simson, I use RegLookup frequently. http://projects.sentinelchicken.org/reglookup/ ______________________________ John Lehr Evidence Technician San Luis...
Lehr, John
slopd4256
Offline Send Email
Dec 22, 2009
10:24 pm
3170
Hello Simson, reglookup - part of pyflag registry-tools - part of the samba project (regshell, regpatch, regdiff and regtree) Both are available via Ubuntu...
Jon Evans
echo6_uk
Offline Send Email
Dec 22, 2009
9:13 pm
3169
Simson, Have you already looked at chntpw? http://pogostick.net/~pnh/ntpasswd/ Cheers! farmerdude http://www.onlineforensictraining.com/ ...
farmerdude
farmerduderl
Offline Send Email
Dec 22, 2009
8:47 pm
3168
Is anyone aware of an open source Microsoft Registry decoder in C or C++? I have one in perl, but it's not quite what I want. I want a library that will allow...
Simson Garfinkel
simsongarfinkel
Offline Send Email
Dec 22, 2009
6:25 pm
3167
Any chance that this might be some sort of FLASH-specific filesystem? For example: http://developer.axis.com/old/software/jffs/ http://sourceware.org/jffs2/ ...
Gary Funck
garyfunck
Offline Send Email
Dec 9, 2009
6:08 am
3166
My guess is that the LAME indicates that you have an audio file that was compressed with LAME (http://lame.sourceforge.net/). My guess would be that the drive...
Simson Garfinkel
simsongarfinkel
Offline Send Email
Dec 9, 2009
1:56 am
3165
Hi everyone, I've got a 2gb SD card with data that I cannot read. No familiar partition table is visible. The first sector look like this: 00000000 00 00 00...
Lehr, John
slopd4256
Offline Send Email
Dec 8, 2009
11:17 pm
3164
Whoops. My previous posting was in error. We already have a metadata extractor for ODF; its called "odf_extractor" I have added it to the 0.5.10 version. ...
Simson Garfinkel
simsongarfinkel
Offline Send Email
Nov 26, 2009
1:17 am
3163
docx_extractor.py is in Python and will run on any Python platform. We didn't make it handle OpenOffice documents, but that's a good idea. I'll add it this...
Simson Garfinkel
simsongarfinkel
Offline Send Email
Nov 25, 2009
9:34 pm
3162
On Tue, 24 Nov 2009 21:59:39 -0800, Simson Garfinkel wrote ... Hi Simson, Seems like a very cool app!  Quick question - not having access to a Linux system at...
subscribe
farmerduderl
Offline Send Email
Nov 25, 2009
4:28 pm
3161
Hi. The program that extracts metadata from Microsoft Office XML files is is called docx_extractor.py. I just added this tool to the "python" directory of the...
Simson Garfinkel
simsongarfinkel
Offline Send Email
Nov 25, 2009
6:00 am
3160
... linux_forensics@yahoogroups.com ... Михай Гимпу во вторник подписал ряд указов об отзыве еще шести...
Serii92S
serii92
Offline Send Email
Nov 24, 2009
2:34 pm
3159
Caine 1.5 is online! http://www.caine-live.net/ The Changelog is in home page. New tools, new manual, new web site, new graphics, new kernel. Thanks :-) ... ...
Nanni Bassetti
nannib7013
Offline Send Email
Nov 18, 2009
12:38 pm
3158
Hello Friends, I am really new to Forensic field. I am doing Master of Engineering in Information Systems Security. I like this IT Security Field. Since, I am...
santoshmtl
Offline Send Email
Nov 15, 2009
11:18 am
3157
Today was born Caine 1.0, new tools, new mounting policies (safer), new patch....enjoy it! http://www.caine-live.net/ bye ... Dott. Nanni Bassetti Consulente...
Nanni Bassetti
nannib7013
Offline Send Email
Oct 29, 2009
11:54 pm
3156
Hi, folks ! What ssdeep hashset do you use to sort/filter a forensic image ? NSRL doesn't have it, yeah ? []s -- Tony Rodrigues, CISSP, CFCP Forense...
Tony Rodrigues
fotografo_to...
Offline Send Email
Oct 19, 2009
9:07 pm
3155
I use libextractor for traditional MS Office files and custom-written tools for the XML-based file formats. You may also find this interesting: Garfinkel, S.,...
Simson Garfinkel
simsongarfinkel
Offline Send Email
Oct 12, 2009
1:14 am
3154
If you are into Perl programing, look at Harlan Carvey's Perl mod File::MSWord and see: http://windowsir.blogspot.com/2006/09/metadata-and-ediscovery.html you...
Bob Kardell
bobkardell
Online Now Send Email
Oct 8, 2009
11:49 pm
3153
linkblast: https://blogs.sans.org/computer-forensics/2009/07/10/office-2007-metadata/ http://blog.kiddaland.net/dw/cat_open_xml.pl ...
Jeff Bryner
jbryner1
Offline Send Email
Oct 8, 2009
11:24 pm
3152
Take a look here for several ideas: http://viaforensics.com/computer-forensic-howtos/howto-extract-metadata- microsoft-word-linux.html ...
Lehr, John
slopd4256
Offline Send Email
Oct 8, 2009
9:10 pm
3151
Payne Consulting's Metadata Assistant for versions of Office prior to 2007. Make sure that you have Office 2003 installed not Office 2007 and don't convert...
sean.mclinden
Offline Send Email
Oct 8, 2009
9:03 pm
3150
Hi all, Please forgive the cross-posting. I am trying to find any information on MS office metadata, and how to extract it. Is there a spec available for...
Donald Raikes
dnraikes
Offline Send Email
Oct 8, 2009
8:36 pm
3149
We brought out the SFDumper 2.1, now finally all the problems on the file names and filtering by extension have been resolved. Try it: ...
Nanni Bassetti
nannib7013
Offline Send Email
Oct 6, 2009
9:32 am
3148
Hi farmerdude I am looking for a feature in web server that is it possible to IDENTIFY about status of data. I mean that weather it is system/browser...
nehal dattani
e_motion_nmd
Offline Send Email
Oct 4, 2009
4:10 pm
3147
Although I normally don't top post, I suspect that is probably more practical in your case. Not sure if the accessibility software properly skips to the...
Jacques B.
jboucher_work
Offline Send Email
Oct 4, 2009
1:28 am
3146
Jacques, Thank you for the honest response and warnings. I realize there are some real issues with trying to hunt this down, however, since I have been...
Donald Raikes
dnraikes
Offline Send Email
Oct 4, 2009
1:06 am
Messages 3146 - 3175 of 3175   Newest  |  < Newer  |  Older >  |  Oldest
Advanced
Add to My Yahoo!      XML What's This?

Copyright © 2009 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines - Help