Search the web
Sign In
New User? Sign Up
linux_forensics
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Want your group to be featured on the Yahoo! Groups website? Add a group photo to Flickr.

Best of Y! Groups

   Check them out and nominate your group.
Having problems with message search? Fill out this form to ensure your group is one of the first to be migrated to the new message search system.

Messages

  Messages Help
Advanced
Messages 828 - 857 of 3157   Oldest  |  < Older  |  Newer >  |  Newest
Messages: Simplify | Expand   (Group by Topic) Author Sort by Date ^
828
I apologize in advance for the all-caps message...but this post is derived from a National Law Enforcement Telecommunications System (NLETS) message that I...
Chris Poldervaart
chrispolderv...
Offline Send Email
Oct 1, 2004
5:13 pm
829
Have a hard drive here (off a laptop) that's alleged to have uploaded a film to a Web Page (and or sent by email) - (I'm still imaging so not looked at the...
IanC
devorg
Offline Send Email
Oct 1, 2004
6:13 pm
830
... The short answer is "Yes". Using a TV capture card (a cheap one is about $30) a person can capture the video from the camera and convert it to formats such...
Preston Boyington
PBoyington@...
Send Email
Oct 1, 2004
7:32 pm
831
Ian I also found very little on this camera. There is a feature breakdown at http://www.supersonic.com/pvl657.htm and there is a manual available through...
M J
njinvestigators
Offline Send Email
Oct 1, 2004
8:07 pm
832
M J wrote: <snipped> ... there are several that are USB. one that comes to mind is here: http://www.hauppauge.com/html/usb_data.htm Preston...
Preston Boyington
PBoyington@...
Send Email
Oct 1, 2004
8:26 pm
833
... Theoretically yes, likely that it's direct, no. They most likely used some sort of adapter, an Adaptec unit, or a Dazzle unit. Or a capture card....
The Dog's Bollix
ISXPRO
Offline Send Email
Oct 1, 2004
10:31 pm
834
Thanks Preston, Martin & Tony. All good advice and it's helping me a lot. I appreciate it. ~~~ PS: That WinTV-USB thing looks good!! I'm going to go out & buy...
IanC
devorg
Offline Send Email
Oct 2, 2004
6:23 pm
835
It's being alleged that a drive was thrown into a computer just before Law Enforcement seized the computer, ie: client heard they were coming and they found...
IanC
devorg
Offline Send Email
Oct 2, 2004
7:09 pm
836
... Ian- could the answer possibly reside in th registry?...
Michael Harrington
chimpinlinux
Offline Send Email
Oct 2, 2004
7:27 pm
837
... I don't think so because on my tests the drives won't boot to start with, let alone hit the registry. I did hear that it is set in a particular sector of...
IanC
devorg
Offline Send Email
Oct 2, 2004
7:47 pm
838
... well my guess would be somewhere in the MBR...I would assume this because it must check the hardware etc before it boots...dont really know either...
Michael Harrington
chimpinlinux
Offline Send Email
Oct 2, 2004
8:14 pm
839
Ian Take a look at http://aumha.org/win5/a/wpa.htm In particular, there is a section on reformatting a disk and a tool to transfer the first sector. It gives...
M J
njinvestigators
Offline Send Email
Oct 2, 2004
8:18 pm
840
It's always been my impression that, since NT4, Windows builds its kernel based on the hardware in existence at the time the OS is installed, then builds onto...
Steve Burgess
imsteve_us
Offline Send Email
Oct 2, 2004
8:24 pm
841
Thanks Martin.. That explained it for me. ~~~~ For your question: "How computer literate is the client? Would he know enough about computers to have used a...
IanC
devorg
Offline Send Email
Oct 2, 2004
9:02 pm
842
... they ... because ... Possibly the client didnt do the crime either. Guess they need to base their judgements on evidence present. ... the ... Thats the...
Enda Cronnolly
endacronnolly
Offline Send Email
Oct 2, 2004
9:40 pm
843
... Nope. All the contents on the NT cd's are pre-built binaries. ... An OS is merely the sum of the files on the disk, and nothing more. There is no magic...
Enda Cronnolly
endacronnolly
Offline Send Email
Oct 2, 2004
9:50 pm
844
What Enda states is correct. I have very recently rebuilt a client's machine (laptop) that I had imaged for a case in which he was involved. Lucky for him I...
The Dog's Bollix
ISXPRO
Offline Send Email
Oct 2, 2004
11:00 pm
845
Hello all, Long time lurker, first time poster. I've been tasked with examining a hard drive running an unknown Windows system for the Prosecutors office in a...
Christopher M. Taylor
ctaylor156rpd
Offline Send Email
Oct 3, 2004
6:33 am
846
... Cor!! Crisis Negotiator!!! My wife could do with your assistance on a daily basis!! :-) ~~~~ Anyway,, back to the question: There's a few ways to do this...
IanC
devorg
Offline Send Email
Oct 3, 2004
4:28 pm
847
This information may or may not be helpful with your case...but Windows XP does keep track of mounted volumes in the System Hive of the registry. This...
Chris Poldervaart
chrispolderv...
Offline Send Email
Oct 4, 2004
8:20 pm
848
See...should have proof read better before I hit the send key.....Didn't hit me that I mistyped the info until after!!! Exchange 8 bytes for 4 bytes and 12...
Chris Poldervaart
chrispolderv...
Offline Send Email
Oct 4, 2004
8:31 pm
849
I saw an iLook report today that showed: ~~~~ MT001I Beginning Ext2FS mapping for partition (11) MT024E Failed to map partition (11) MU027E Error detected...
IanC
devorg
Offline Send Email
Oct 4, 2004
8:37 pm
850
"should have proof read better before I hit the send key" i Have thAt problim too... Chris :-) Good info mate,, thank you.....
IanC
devorg
Offline Send Email
Oct 4, 2004
8:49 pm
851
Refinancing your home has never been easier and more profitable. Our staff works exclusively to save you as much money as possible on any home loan. We secure...
l7g3688
Offline Send Email
Oct 4, 2004
10:31 pm
852
Quoting: "IanC" ... 11 ... I guess you'd need to be LEO to know that answer for certain, however, it would be correct forensic procedure to document everything...
Enda Cronnolly
endacronnolly
Offline Send Email
Oct 4, 2004
10:40 pm
853
... Well yes I totally agree that we should look at all angles but if LE have something that at a press of a button will see all possible available partitions...
IanC
devorg
Offline Send Email
Oct 4, 2004
11:54 pm
854
... Maybe you're better off the way you are. Just because a software package reports it has done it, doesn't necessarily mean that the best current thinking...
Enda Cronnolly
endacronnolly
Offline Send Email
Oct 5, 2004
12:29 am
855
here here an excellent point ... From: "IanC" <saladin@...> To: <linux_forensics@yahoogroups.com> Sent: Monday, October 04, 2004 7:57 PM Subject: RE:...
Melissa Royer
defender03102
Offline Send Email
Oct 5, 2004
12:39 am
856
A long time ago I had some interesting experiences with partition reading "tools". I used testdisk and gpart and both found either incorrect information...
The Dog's Bollix
ISXPRO
Offline Send Email
Oct 5, 2004
4:02 am
857
Hi friends, I would like to know best recommended tools(open source and commercial) for internet and e-commerce related crime analysis.Your comments would be...
gsrao@...
raohyd
Offline Send Email
Oct 5, 2004
6:43 am
Messages 828 - 857 of 3157   Oldest  |  < Older  |  Newer >  |  Newest
Advanced
Add to My Yahoo!      XML What's This?

Copyright © 2009 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines - Help