Re: [sleuthkit-users] Novell Filesystem
Brought to you by:
carrier
From: Brian C. <ca...@sl...> - 2003-07-24 19:57:06
|
On 24 Jul 2003 12:45 PDT you wrote: > I have a Novell Filesystem Image file. > > How would I examine this file? It does not appear that the Sleuth kit > supports the NCPFS (Novell Filesystem). Any suggestions? There was a thread on this a while back forensics@securityfocus. http://lists.jammed.com/forensics/2002/07/index.html#17 It lists a Linux driver and ontrack. If you can get it mounted read only under Linux, then you can use mac-robber to collect the MAC times and make a timeline of activity with 'mactime' in The Sleuth Kit. brian |