Re: [sleuthkit-developers] Other FS
Brought to you by:
carrier
|
From: Brian C. <ca...@sl...> - 2004-04-02 14:43:49
|
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
On Apr 2, 2004, at 8:09 AM, MXrcio Carneiro wrote:
> Hi!
>
> I'm preparing a course about Linux Forensics (mainly about file
> system). Of course Sleuth and Autopsy is the main tool (I want to show
> FLAG, but I'm having a hard time to install it - maybe should look for
> the Live CD?).
Great. If you send me the link, I'll add it to the links page.
> But, I have a issue about other filesystem than ext{2,3}. Does anybody
> knows what are the available tools for forensic analysis in Reiser and
> XFS filesystems? Are there plans to add this to Sleuth Kit?
I know of people who have talked about implementing Reiser, but nothing
has been done as far as I know. There is someone working on JFS. I
don't think I've heard of anyone doing XFS. I don't have plans to add
these in the near future. I'm actually more inclined to add HFS+
before any of the Linux-based ones.
brian
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (Darwin)
iD8DBQFAbXwaOK1gLsdFTIsRAtviAJ9FW/T/oH23Z5w+eiSshfGvf4GvDACeOpzf
tautD44QmPwQaEW5Crz7wqw=
=6akc
-----END PGP SIGNATURE-----
|