Search the web
Sign In
New User? Sign Up
linux_forensics
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Want to share photos of your group with the world? Add a group photo to Flickr.

Best of Y! Groups

   Check them out and nominate your group.
Having problems with message search? Fill out this form to ensure your group is one of the first to be migrated to the new message search system.

Messages

  Messages Help
Advanced
Messages 687 - 717 of 3157   Oldest  |  < Older  |  Newer >  |  Newest
Messages: Simplify | Expand   (Group by Topic) Author Sort by Date ^
687
from the specs of the M5200 that notebook uses an Intel 855GME graphics controller, which is supported by linux it appears. The following howto will let you...
Enda Cronnolly
endacronnolly
Offline Send Email
Jul 5, 2004
11:14 am
688
You could use the search term [^\x00] in SMART. ... http://us.click.yahoo.com/Z1wmxD/DREIAA/yQLSAA/M4xqlB/TM ... ===== Regards - Andrew Rosen ASR Data...
Andrew Rosen
asrdata
Offline Send Email
Jul 6, 2004
8:26 pm
689
I upgraded, errrr, changed from RH9 to RH Enterprise WS 3.x with the latest 2.4 kernal and after many days of configuring I still have one problem. When I put...
lasvegascop@...
lasvegascop
Offline Send Email
Jul 7, 2004
2:27 am
690
... I'm not sure if I completely understand your question, but I would check two places: 1) /etc/fstab - make sure there are no references to your suspect...
Barry J. Grundy
grundy_b
Offline Send Email
Jul 7, 2004
12:13 pm
691
Just a reminder that this is the last weekend for those interested in attending this year's Digital Forensic Research Workshop (DFRWS) to pay the early...
Kalil Daniel Contr AF...
goatboy1221
Offline Send Email
Jul 9, 2004
4:55 pm
692
Specify the drive in your /etc/fstab and give it the option noauto, this will prevent it being mounted when the mount -a command is given during startup....
Enda Cronnolly
endacronnolly
Offline Send Email
Jul 9, 2004
6:53 pm
693
Hello, is there any open source application able to read Windows Event files? I can read them quite fine with an unicode editor, but only the text of the...
David Barroso
dbbarroso
Offline Send Email
Jul 12, 2004
1:07 pm
694
Thanks Enda. Sorry for the delayed response. I've been out of my office for the last week or so. I appreciate your response, because I'm still playing with...
Luis Salazar
Luis.Salazar@...
Send Email
Jul 14, 2004
2:16 pm
696
NOTE: Resume Submital has been extended until July 30, 2004. This is a great opportunity to work for a highly motivated organization that impacts Law...
Todd Shipley
shipleytg
Offline Send Email
Jul 15, 2004
6:49 pm
697
I've searched high and low for just such a beast, and come up empty handed, so I'm going to say no, there sadly is not. Cory Altheide Senior Network Forensics...
Altheide, Cory B. (IA...
digitalquincy
Offline Send Email
Jul 19, 2004
9:29 pm
698
... Yes, my search was also unsuccessful. I've been able to recover some deleted Evt files thanks to foremost and finally I've been able to proper examine them...
David Barroso
dbbarroso
Offline Send Email
Jul 20, 2004
8:13 am
699
I've got a line on linux based windows event log parser. It's never been publicly released, and I'll check to see if it's okay to put out there. W...
William Salusky
wsalusky
Offline Send Email
Jul 20, 2004
8:55 pm
700
What about using the Wine project (http://www.winehq.com/) to run Windows executables within Linux? Although not perfect, I have been able to run some of the...
Matt Kucenski
kucenskm
Offline Send Email
Jul 21, 2004
12:24 pm
701
... Perhaps pyFlag will be of interest? <http://pyflag.sourceforge.net/> -- Andrew Nielsen <mailto:andrew@...>...
Andrew Nielsen
anielsen2000
Offline Send Email
Jul 21, 2004
12:34 pm
702
While that is a decent enough workaround, it doesn't meet the original requirement: "is there any open source application able to read Windows Event files?" ...
Altheide, Cory B. (IA...
digitalquincy
Offline Send Email
Jul 21, 2004
5:26 pm
703
... PyFLAG is a fantastic tool, but to the best of my knowledge it does not parse Windows event log files, so would not be applicable. Cory Altheide Senior...
Altheide, Cory B. (IA...
digitalquincy
Offline Send Email
Jul 21, 2004
5:30 pm
704
... I've just found a little php application to read Evt files, written by Jamie French from whitehats.ca. It also points out some other resources where there...
David Barroso
dbbarroso
Offline Send Email
Jul 21, 2004
9:35 pm
705
Be sure to check out the Linux labs being held throughout the conference! The HTCIA Mid-Atlantic Chapter is pleased to host the 2004 International Training...
Kaderabek Shawn M
eci3294
Offline Send Email
Jul 28, 2004
8:38 pm
706
Hi *, I like Linux as a "forensic tool" but have an unsolved problem with my backups: How do I create a backup on tape & hd simultaniously? Ok, I've heard of ...
Dietmar Mauersberger
mausburger
Offline Send Email
Jul 30, 2004
12:32 pm
707
... Have a look at tpipe: http://freshmeat.net/projects/tpipe/ I use it to dd and hash a drive at the same time. It basically splits the output stream into...
Barry J. Grundy
grundy_b
Offline Send Email
Jul 30, 2004
12:38 pm
708
Hi Dietmar - My name is Andrew Rosen. I'd like to ask if you'd ... You are correct in that SMART is able to provide the functionality you are seeking, but I'm...
Andrew Rosen
asrdata
Offline Send Email
Jul 31, 2004
12:27 pm
709
We hear alot of great things about Smart but unfortunately we cannot afford it at this time with the non-law enforcement pricing. So right now it's not really...
Donald Jones
dxj3
Offline Send Email
Jul 31, 2004
5:38 pm
710
Hi Andy, my comment had no value. What I ment was that SMART is a great solution for the problem I have, but I want to do it everywhere and at anytime without...
Dietmar Mauersberger
mausburger
Offline Send Email
Aug 2, 2004
6:32 am
711
Dietmar, You can tee your output from dd quite easily. The command line looks like this: dd if=/dev/hdX | tee /mnt/location1 | dd of=/dev/tapedevice A second...
Randall Shane
rshane@...
Send Email
Aug 2, 2004
9:18 am
712
Hi Randall, I know. Thats not the problem. What if the capacity of the tape device is lower than the drive to be imaged? Thats the problem I have. The dd to...
Dietmar Mauersberger
mausburger
Offline Send Email
Aug 2, 2004
9:42 am
713
Dietmar, Let me see if I have this correct, you want to image from a single drive to another drive and also to a tape with less capacity that the drive (?)....
Randall Shane
rshane@...
Send Email
Aug 2, 2004
10:43 am
714
hallo dietmar, have you tried to pipe the output of dd into gzip? for example: # dd if=/dev/hda1 bs=512 | gzip -9 > /safe/place/hda1.dd.gz that results in a...
metax@...
Send Email
Aug 2, 2004
10:54 am
715
Hi Klemens, hi Randall! Compession is unfortunately not enough and to buy a larger tape is not the most desireable solution. The costs for tapes with 400 GB or...
Dietmar Mauersberger
mausburger
Offline Send Email
Aug 2, 2004
1:09 pm
716
Is your tape drive a plain old single tape drive or an autochanger? ... From: "Dietmar Mauersberger" <news@...> To: <linux_forensics@yahoogroups.com>...
Enda Cronnolly
endacronnolly
Offline Send Email
Aug 2, 2004
2:27 pm
717
they are all old single tapes. DDS-4, DLT, SLR....
Dietmar Mauersberger
mausburger
Offline Send Email
Aug 2, 2004
2:40 pm
Messages 687 - 717 of 3157   Oldest  |  < Older  |  Newer >  |  Newest
Advanced
Add to My Yahoo!      XML What's This?

Copyright © 2009 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines - Help