sleuthkit-developers Mailing List for The Sleuth Kit (Page 32)
Brought to you by:
carrier
You can subscribe to this list here.
2003 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
(10) |
Sep
(2) |
Oct
|
Nov
(1) |
Dec
|
---|---|---|---|---|---|---|---|---|---|---|---|---|
2004 |
Jan
(22) |
Feb
(39) |
Mar
(8) |
Apr
(17) |
May
(10) |
Jun
(2) |
Jul
(6) |
Aug
(4) |
Sep
(1) |
Oct
(3) |
Nov
|
Dec
|
2005 |
Jan
(2) |
Feb
(6) |
Mar
(2) |
Apr
(2) |
May
(13) |
Jun
(2) |
Jul
|
Aug
|
Sep
(5) |
Oct
|
Nov
(2) |
Dec
|
2006 |
Jan
|
Feb
|
Mar
(1) |
Apr
|
May
(2) |
Jun
(9) |
Jul
(4) |
Aug
(2) |
Sep
|
Oct
(1) |
Nov
(9) |
Dec
(4) |
2007 |
Jan
(1) |
Feb
(2) |
Mar
|
Apr
(3) |
May
|
Jun
|
Jul
(6) |
Aug
|
Sep
(4) |
Oct
|
Nov
|
Dec
(2) |
2008 |
Jan
(4) |
Feb
|
Mar
|
Apr
(1) |
May
|
Jun
(9) |
Jul
(14) |
Aug
|
Sep
(5) |
Oct
(10) |
Nov
(4) |
Dec
(7) |
2009 |
Jan
(7) |
Feb
(10) |
Mar
(10) |
Apr
(19) |
May
(16) |
Jun
(3) |
Jul
(9) |
Aug
(5) |
Sep
(5) |
Oct
(16) |
Nov
(35) |
Dec
(30) |
2010 |
Jan
(4) |
Feb
(24) |
Mar
(25) |
Apr
(31) |
May
(11) |
Jun
(9) |
Jul
(11) |
Aug
(31) |
Sep
(11) |
Oct
(10) |
Nov
(15) |
Dec
(3) |
2011 |
Jan
(8) |
Feb
(17) |
Mar
(14) |
Apr
(2) |
May
(4) |
Jun
(4) |
Jul
(3) |
Aug
(7) |
Sep
(18) |
Oct
(8) |
Nov
(16) |
Dec
(1) |
2012 |
Jan
(9) |
Feb
(2) |
Mar
(3) |
Apr
(13) |
May
(10) |
Jun
(7) |
Jul
(1) |
Aug
(5) |
Sep
|
Oct
(3) |
Nov
(19) |
Dec
(3) |
2013 |
Jan
(16) |
Feb
(3) |
Mar
(2) |
Apr
(4) |
May
|
Jun
(3) |
Jul
(2) |
Aug
(17) |
Sep
(6) |
Oct
(1) |
Nov
|
Dec
(4) |
2014 |
Jan
(2) |
Feb
|
Mar
(3) |
Apr
(7) |
May
(6) |
Jun
(1) |
Jul
(18) |
Aug
|
Sep
(3) |
Oct
(1) |
Nov
(26) |
Dec
(7) |
2015 |
Jan
(5) |
Feb
(1) |
Mar
(2) |
Apr
|
May
(1) |
Jun
(1) |
Jul
(5) |
Aug
(7) |
Sep
(4) |
Oct
(1) |
Nov
(1) |
Dec
|
2016 |
Jan
(3) |
Feb
|
Mar
(1) |
Apr
|
May
(1) |
Jun
(13) |
Jul
(23) |
Aug
(2) |
Sep
(11) |
Oct
|
Nov
(1) |
Dec
|
2017 |
Jan
(4) |
Feb
|
Mar
|
Apr
(2) |
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
(2) |
Dec
|
2018 |
Jan
|
Feb
|
Mar
(2) |
Apr
|
May
(1) |
Jun
(3) |
Jul
|
Aug
|
Sep
(2) |
Oct
|
Nov
(2) |
Dec
|
2019 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
(2) |
Sep
|
Oct
|
Nov
|
Dec
|
2020 |
Jan
(4) |
Feb
|
Mar
|
Apr
|
May
|
Jun
(3) |
Jul
(5) |
Aug
(1) |
Sep
|
Oct
|
Nov
|
Dec
|
2021 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
(1) |
Dec
|
2024 |
Jan
|
Feb
(1) |
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
(1) |
From: SourceForge.net <no...@so...> - 2009-01-13 05:23:40
|
Bugs item #2503552, was opened at 2009-01-13 00:23 Message generated for change (Tracker Item Submitted) made by Item Submitter You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=477889&aid=2503552&group_id=55685 Please note that this message will contain a full copy of the comment thread, including the initial issue submission, for this request, not just the latest update. Category: File System Tools Group: None Status: Open Resolution: None Priority: 5 Private: No Submitted By: Brian Carrier (carrier) Assigned to: Brian Carrier (carrier) Summary: Missing ISO9660 Files Initial Comment: In the attached ISO, files are missing from the root directory. Reported by Tom Black. ---------------------------------------------------------------------- You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=477889&aid=2503552&group_id=55685 |
From: SourceForge.net <no...@so...> - 2009-01-06 18:10:14
|
Bugs item #2490550, was opened at 2009-01-06 13:10 Message generated for change (Tracker Item Submitted) made by Item Submitter You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=477889&aid=2490550&group_id=55685 Please note that this message will contain a full copy of the comment thread, including the initial issue submission, for this request, not just the latest update. Category: File System Tools Group: None Status: Open Resolution: None Priority: 5 Private: No Submitted By: david kennedy (dmkennedy) Assigned to: Nobody/Anonymous (nobody) Summary: fls -r missing visible folders/files in NTFS, 2.52 and 3.0.0 Initial Comment: I have a disk with one NTFS partition that isn't showing some folders and files through fls -r. I've verified the file is missing in 3.0.0 as well as 2.52. I can't share the image itself; it has a bit of sensitive data. The folder turns up just fine in windows and linux. In a specific example, FLS is missing the folder and all files within it. The folder's inode number SHOULD be 30211 (located via another tool). istat gives the proper folder name in its output when directly accessing the inode. The folder's parent inode is 25442 on this image. Below is an istat for both the missing folder and the (fls-visible) parent folder, for both 3.0.0 and 2.52. Sleuthkit 2.52: istat for parent folder: istat /dev/sdb1 25442 MFT Entry Header Values: Entry: 25442 Sequence: 1 $LogFile Sequence Number: 16787693 Allocated Directory Links: 1 $STANDARD_INFORMATION Attribute Values: Flags: Archive Owner ID: 0 Created: Fri Dec 17 13:50:43 2004 File Modified: Fri Dec 17 13:54:38 2004 MFT Modified: Fri Dec 17 13:54:38 2004 Accessed: Tue Oct 28 14:17:49 2008 $FILE_NAME Attribute Values: Flags: Directory, Archive Name: I386 Parent MFT Entry: 2385 Sequence: 2408 Allocated Size: 0 Actual Size: 0 Created: Fri Dec 17 13:50:43 2004 File Modified: Fri Dec 17 13:54:38 2004 MFT Modified: Fri Dec 17 13:54:38 2004 Accessed: Fri Dec 17 13:54:38 2004 $ATTRIBUTE_LIST Attribute Values: Type: 16-0 MFT Entry: 25442 VCN: 0 Type: 48-2 MFT Entry: 25442 VCN: 0 Type: 144-9 MFT Entry: 25442 VCN: 0 Type: 160-1 MFT Entry: 27750 VCN: 0 Type: 160-11 MFT Entry: 25442 VCN: 1616 Type: 176-10 MFT Entry: 25442 VCN: 0 Attributes: Type: $STANDARD_INFORMATION (16-0) Name: N/A Resident size: 72 Type: $ATTRIBUTE_LIST (32-12) Name: N/A Resident size: 224 Type: $FILE_NAME (48-2) Name: N/A Resident size: 74 Type: $INDEX_ROOT (144-9) Name: $I30 Resident size: 56 Type: $INDEX_ALLOCATION (160-11) Name: $I30 Non-Resident size: 921600 9226806 9226807 9226808 9226809 9226810 9226811 9226812 9226813 8279563 8279564 8279565 8279566 8279567 8279568 8279569 8279570 8279583 8279584 8279585 8279586 8279587 8279588 8279589 8279590 562606 562607 562608 562609 562610 562611 562612 562613 4975729 4975730 4975731 4975732 4975733 4975734 4975735 4975736 5201957 5201958 5201959 5201960 5201961 5201962 5201963 5201964 6230377 6230378 6230379 6230380 6230381 6230382 6230383 6230384 6474510 6474511 6474512 6474513 6474514 6474515 6474516 6474517 6474518 6474519 6474520 6474521 6474522 6474523 6474524 6474525 6474769 6474770 6474771 6474772 6474773 6474774 6474775 6474776 7386954 7386955 7386956 7386957 7386958 7386959 7386960 7386961 8130144 8130145 8130146 8130147 8130148 8130149 8130150 8130151 8130260 8130261 8130262 8130263 8130264 8130265 8130266 8130267 8435605 8435606 8435607 8435608 8435609 8435610 8435611 8435612 9253264 9253265 9253266 9253267 9253268 9253269 9253270 9253271 12968399 12968400 12968401 12968402 12968403 12968404 12968405 12968406 12968619 12968620 12968621 12968622 12968623 12968624 12968625 12968626 8014380 8014381 8014382 8014383 8014384 8014385 8014386 8014387 4793927 4793928 4793929 4793930 4793931 4793932 4793933 4793934 6718054 6718055 6718056 6718057 6718058 6718059 6718060 6718061 6718701 6718702 6718703 6718704 6718705 6718706 6718707 6718708 6718709 6718710 6718711 6718712 6460765 6460766 6460767 6460768 8137826 8137827 8137828 8137829 8137830 8137831 8137832 8137833 Type: $BITMAP (176-10) Name: $I30 Resident size: 32 Type: $INDEX_ALLOCATION (160-1) Name: $I30 Non-Resident size: 921600 11830897 11830898 11830899 11830900 11830901 11830902 11830903 11830904 6029520 6029521 6029522 6029523 6029524 6029525 6029526 6029527 6029528 7956180 7956181 7956182 7956183 7956184 7956185 7956186 5620477 5620478 5620479 5620480 5620481 5620482 5620483 5620484 6156845 6156846 6156847 6156848 6156849 6156850 6156851 6156852 6156853 6156854 6156855 6156856 13093078 13093079 13093080 13093081 8796948 8796949 8796950 8796951 8796952 8796953 8796954 8796955 8027697 8027698 8027699 8027700 8027701 8027702 8027703 8027704 8027705 8027706 1630032 1630033 1630034 1630035 1630036 1630037 8918311 8918312 8918313 8918314 8918315 8918316 8918317 8918318 11905949 11905950 11905951 11905952 11905953 11905954 11905955 11905956 11935107 11935108 11935109 11935110 11935111 11935112 11935113 11935114 11935451 11935452 11935453 11935454 11935455 11935456 11935457 11935458 7877375 7877376 7877377 7877378 7877379 7877380 7877381 7877382 7877383 7877384 7877385 7877386 12826824 12826825 12826826 12826827 7338851 7338852 7338853 7338854 7338855 7338856 7338857 7338858 7338859 7338860 7338861 7338862 7338863 7338864 7338865 7338866 7338867 7338868 7338869 7338870 7338871 7338872 911045 911046 483475 483476 483477 483478 483479 483480 483481 483482 483483 483484 483485 483486 483487 483488 483489 483490 483491 483492 483493 483494 483495 483496 483497 6200808 8181505 8181506 8181507 8181508 8181509 8181510 8181511 8181512 8181513 8181514 8181515 8181516 8181517 8181518 8181519 8181520 4792800 4792801 4792802 4792803 4792804 4792805 4792806 4792807 12894781 12894782 12894783 12894784 12894785 12894786 12894787 12894788 189926 189927 189928 189929 189930 189931 189932 189933 189934 189935 189936 189937 189938 189939 189940 189941 8495448 8495449 8495450 8495451 8495452 8495453 8495454 8495455 8495456 8495457 5257243 5257244 5257245 5257246 5257247 5257248 1730855 1730856 1730857 1730858 1730859 1730860 1730861 1730862 6255617 6255618 6255619 6255620 6255621 6255622 6255623 6255624 8703778 8703779 8703780 8703781 8703782 8703783 8703784 8703785 8703786 8703787 5249521 5249522 5249523 5249524 5249525 5249526 7429665 7429666 7429667 7429668 7429669 7429670 7429671 7429672 955410 955411 955412 955413 955414 955415 955416 955417 970234 970235 970236 970237 970238 970239 970240 970241 970242 970243 970244 970245 970246 970247 970248 970249 970250 970251 970252 970253 970254 970255 970256 970257 970258 970259 970260 970261 970262 970263 970264 970265 970266 970267 970268 970269 970270 970271 970272 970273 970274 1557599 1557600 1557601 1557602 1557603 1557604 1557605 6034494 6034495 6034496 6034497 6034498 6034499 6034500 6034501 6034502 6034503 6034504 8158321 8158322 8158323 8158324 8158325 8158326 1431535 1431536 1431537 1431538 1431539 1431540 1431541 6295104 6295105 6295106 6295107 6295108 6295109 6295110 6295111 6295112 1603567 1603568 1603569 1603570 1603571 1603572 1603573 4921710 4921711 4921712 4921713 4921714 4921715 4921716 4921717 6584244 6584245 6584246 6584247 6584248 6584249 6584250 6584251 6584410 6584411 6584412 6584413 6584414 6584415 6584416 6584417 6584418 6584419 6584420 6584421 6584422 6584423 6584424 6038872 8025645 8025646 8025647 8025648 8025649 8025650 8025651 8025652 6941873 6941874 6941875 6941876 6941877 6941878 6941879 6941880 6496837 6496838 6496839 6496840 6496841 6496842 6496843 6496844 7114588 7114589 7114590 7114591 7114592 7114593 7114594 7114595 7560642 7560643 7560644 7560645 7560646 7560647 7560648 7560649 7331575 7331576 7331577 7331578 7331579 7331580 7331581 7331582 8083048 8083049 8083050 8083051 8083052 8083053 8083054 8083055 8083056 8083057 8083058 8083059 8083060 8083061 8083062 8083063 8083267 8083268 8083269 8083270 8083271 8083272 8083273 8083274 7377776 7377777 7377778 7377779 7377780 7377781 7377782 7377783 7377784 1661551 1661552 1661553 1661554 1661555 1661556 1661557 8581712 8581713 8581714 8581715 8581716 8581717 8581718 8581719 6560848 6560849 6560850 6560851 6560852 6560853 6560854 6560855 7600800 7600801 7600802 7600803 7600804 7600805 7600806 7600807 7600808 7600809 7600810 424818 424819 424820 424821 424822 424823 424824 436269 436270 436271 436272 436273 436274 436275 1748431 1748432 1748433 1748434 1748435 1748436 1748437 7632690 7632691 7632692 7632693 7632694 7632695 7632696 7632697 7632698 1749727 1749728 1749729 1749730 1749731 1749732 1749733 7627565 7627566 7627567 7627568 7627569 7627570 7627571 7627572 7627573 7627574 7627575 7627576 7627577 7627578 5834854 5834855 6505643 6505644 6505645 6505646 6505647 6505648 6505649 6505650 6506094 6506095 6506096 6506097 6506098 6506099 6506100 6506101 6506102 6506103 6506104 7363444 7363445 7363446 7363447 7363448 9009489 9009490 9009491 9009492 9009493 9009494 9009495 9009496 9009497 9009498 9009499 644210 644211 644212 644213 644214 644215 644216 660561 660562 660563 660564 660565 660566 660567 1408287 1408288 1408289 1408290 1408291 1408292 1408293 13082746 13082747 13082748 13082749 13082750 13082751 13082752 13082753 4973895 4973896 4973897 4973898 4973899 4973900 4973901 4973902 4973903 4973904 4973905 4973906 4973907 4973908 4973909 4973910 5499122 5499123 5499124 5499125 5499126 5499127 5499128 5499129 5686844 5686845 5686846 5686847 5686848 5686849 5686850 5686851 6049242 6049243 6049244 6049245 6049246 6049247 6049248 6049249 6049250 6049251 6049252 6049253 6049254 6049255 6049256 5501192 6251883 6251884 6251885 6251886 6251887 6251888 6251889 6251890 7625262 7625263 7625264 7625265 7625266 7625267 7625268 7625269 8284704 8284705 8284706 8284707 8284708 8284709 8284710 8284711 8284712 8284713 8284714 972343 972344 972345 972346 972347 972348 972349 1015127 1015128 1015129 1015130 1015131 1015132 1015133 1750367 1750368 1750369 1750370 1750371 1750372 1750373 5868453 5868454 5868455 5868456 5868457 5868458 5868459 5868460 8729227 8729228 8729229 8729230 8729231 8729232 8729233 8729234 8139874 8139875 8139876 8139877 8139878 8139879 8139880 8139881 7792415 7792416 7792417 7792418 7792419 7792420 7792421 7792422 7792423 7792424 7792425 7792426 1037517 1037518 1037519 1037520 1037521 1037522 1037523 1037533 1037534 1037535 1037536 1037537 1037538 1037539 1037581 1037582 1037583 1037584 1037585 1037586 1037587 1750719 1750720 1750721 1750722 1750723 1750724 1750725 798615 798616 798617 798618 798619 798620 798621 798622 798623 1750687 1750688 1750689 1750690 1750691 1750692 1750693 8707871 8707872 8707873 8707874 8707875 8707876 8707877 8707878 9031436 9031437 9031438 9031439 9031440 9031441 9031442 9031443 9031507 9031508 9031509 9031510 9031511 9031512 9031513 9031514 9031714 9031715 9031716 9031717 9031718 9031719 9031720 9031721 9031835 9031836 9031837 9031838 9031839 9031840 9031841 9031842 9031893 9031894 9031895 9031896 9031897 9031898 9031899 9031900 9032007 9032008 9032009 9032010 9032011 9032012 9032013 9032014 13069964 13069965 13069966 13069967 13069968 13069969 13069970 13069971 13070040 13070041 13070042 13070043 13070044 13070045 13070046 13070047 6051815 6051816 6051817 6051818 6051819 6051820 6051821 6051822 6071155 6071156 6071157 6071158 6071159 6071160 6071161 6071162 5387047 5387048 5387049 5387050 5387051 5387052 5387053 5387054 4691541 4691542 4691543 4691544 4691545 4691546 4691547 4691548 4691549 4691550 4691551 4691552 13070551 13070552 13070553 13070554 6079186 6079187 6079188 6079189 6079190 6079191 6079192 6079193 6413336 6413337 6413338 6413339 6413340 6413341 6413342 6413343 6413615 6413616 6413617 6413618 6413619 6413620 6413621 6413622 6900908 6900909 6900910 6900911 6900912 6900913 6900914 6900915 6900916 6900917 6900918 6900919 6900920 7346036 7346037 7346038 7346039 7346040 5932790 5932791 5932792 5932793 5932794 5932795 5932796 11827873 11827874 11827875 11827876 11827877 11827878 11827879 6306321 6306322 6306323 6306324 6306325 6306326 6306327 6306328 6092384 6092385 6092386 6092387 6092388 6092389 6092390 6092391 6092392 9401258 9401259 9401260 9401261 9401262 9401263 9401264 12955292 12955293 12955294 12955295 12955296 12955297 12955298 12955299 5112514 5112515 5112516 5112517 5112518 5112519 5112520 5112521 6911569 6911570 6911571 6911572 6911573 6911574 6911575 6911576 7101353 7101354 7101355 7101356 7101357 7101358 7101359 7101360 7101361 7101362 7101363 7101364 7101365 7101366 7101367 7101368 8712977 8712978 8712979 8712980 8712981 8712982 8712983 8712984 5334493 5334494 5334495 5334496 5334497 5334498 5334499 5334500 5334501 5334502 5334503 5334504 8359749 8359750 8359751 8359752 8359753 8359754 6544098 6544099 6544100 6544101 6544102 6544103 6544104 9337407 9337408 9337409 9337410 9337411 9337412 9337413 7552788 7552789 7552790 7552791 7552792 7552793 7552794 7552795 7553437 7553438 7553439 7553440 7553441 7553442 7553443 7553444 7553562 7553563 7553564 7553565 7553566 7553567 7553568 7553569 8792587 8792588 8792589 8792590 8792591 8792592 8792593 8792594 8792746 8792747 8792748 8792749 8792750 8792751 8792752 8792753 9214228 9214229 9214230 9214231 9214232 9214233 9214234 9214235 9214430 9214431 9214432 9214433 9214434 9214435 9214436 9214437 9214514 9214515 9214516 9214517 9214518 9214519 9214520 9214521 1030435 1030436 1030437 1030438 1030439 1030440 1030441 1030442 1030716 1030717 1030718 1030719 1030720 1030721 1030722 1030723 5264752 5264753 5264754 5264755 5264756 5264757 5264758 5264759 5265093 5265094 5265095 5265096 5265097 5265098 5265099 5265100 5265101 5621181 5621182 5621183 5621184 5621185 5621186 5621187 6891679 6891680 6891681 6891682 6891683 6891684 6891685 6891686 6891687 6891688 6891689 6891690 6891691 6891692 6891693 6891694 8104855 8104856 8104857 8104858 8104859 8104860 8104861 8104862 8104863 8104864 8104865 8104866 8104867 8104868 8104869 8104870 5227582 5227583 5227584 5227585 5227586 5227587 5227588 5227589 5227590 5227591 5227592 5227593 518818 518819 518820 518821 5375875 5375876 5375877 5375878 5375879 5375880 5375881 5375882 5403195 5403196 5403197 5403198 5403199 5403200 5403201 5403202 5403203 5403204 5403205 5403206 5403207 5403208 5403209 5403210 6064004 6064005 6064006 6064007 6064008 6064009 6064010 6064011 6179671 6179672 6179673 6179674 6179675 6179676 6179677 6179678 6315651 6315652 6315653 6315654 6315655 6315656 6315657 6315658 6705103 6705104 6705105 6705106 6705107 6705108 6705109 6705110 6705317 6705318 6705319 6705320 6705321 6705322 6705323 6705324 7744529 7744530 7744531 7744532 7744533 7744534 7744535 7744536 7745137 7745138 7745139 7745140 7745141 7745142 7745143 7745144 7903260 7903261 7903262 7903263 7903264 7903265 7903266 7903267 7968689 7968690 7968691 7968692 7968693 7968694 7968695 7968696 8113815 8113816 8113817 8113818 8113819 8113820 8113821 8113822 8539299 8539300 8539301 8539302 8539303 8539304 8539305 8539306 8572209 8572210 8572211 8572212 8572213 8572214 8572215 8572216 12760230 12760231 12760232 12760233 12760234 12760235 12760236 12760237 517148 517149 517150 517151 517152 517153 517154 517155 517367 517368 517369 517370 517371 517372 517373 517374 768822 768823 768824 768825 768826 768827 768828 768829 6071580 6071581 6071582 6071583 6071584 6071585 6071586 6071587 6072178 6072179 6072180 6072181 6072182 6072183 6072184 6072185 7001616 7001617 7001618 7001619 7001620 7001621 7001622 7001623 8400304 8400305 8400306 8400307 8400308 8400309 8400310 8400311 8400659 8400660 8400661 8400662 8400663 8400664 8400665 8400666 6210287 6210288 6210289 6210290 6210291 6210292 6210293 6210294 6212587 6212588 6212589 6212590 6212591 6212592 6212593 6212594 7567875 7567876 7567877 7567878 7567879 7567880 7567881 7567882 7531829 7531830 7531831 7531832 7531833 7531834 7531835 7531836 7531837 7531838 7531839 7531840 7531841 7531842 7531843 7531844 7531887 7531888 7531889 7531890 7531891 7531892 7531893 7531894 7206226 7206227 7206228 7206229 7206230 7206231 7206232 7206233 7206767 7206768 7206769 7206770 7206771 7206772 7206773 7206774 7206775 7206776 8049832 8049833 8049834 8049835 8049836 8049837 4987819 4987820 4987821 4987822 4987823 4987824 4987825 4987826 4988328 4988329 4988330 4988331 4988332 4988333 4988334 4988335 6074929 6074930 6074931 6074932 6074933 6074934 6074935 6074936 6075275 6075276 6075277 6075278 6075279 6075280 6075281 6075282 6075283 6075284 6075285 6075286 6075287 6075288 185018 185019 9087980 9087981 9087982 9087983 9087984 9087985 9087986 9087987 9088043 9088044 9088045 9088046 9088047 9088048 9088049 9088050 13112758 13112759 13112760 13112761 13112762 13112763 13112764 13112765 6744132 6744133 6744134 6744135 6744136 6744137 6744138 6744139 7639596 7639597 7639598 7639599 7639600 7639601 7639602 7639603 8715965 8715966 8715967 8715968 8715969 8715970 8715971 8715972 6073220 6073221 6073222 6073223 6073224 6073225 6073226 6073227 7208816 7208817 7208818 7208819 7208820 7208821 7208822 7208823 7208824 225944 225945 225946 225947 225948 225949 225950 9226706 9226707 9226708 9226709 9226710 9226711 9226712 9226713 istat for missing folder: istat /dev/sdb1 30211 MFT Entry Header Values: Entry: 30211 Sequence: 1 $LogFile Sequence Number: 16790486 Allocated Directory Links: 1 $STANDARD_INFORMATION Attribute Values: Flags: Archive Owner ID: 0 Created: Fri Dec 17 13:54:08 2004 File Modified: Fri Dec 17 13:54:08 2004 MFT Modified: Fri Dec 17 13:54:08 2004 Accessed: Tue Oct 28 14:18:01 2008 $FILE_NAME Attribute Values: Flags: Directory, Archive Name: UNIPROC Parent MFT Entry: 25442 Sequence: 1 Allocated Size: 0 Actual Size: 0 Created: Fri Dec 17 13:54:08 2004 File Modified: Fri Dec 17 13:54:08 2004 MFT Modified: Fri Dec 17 13:54:08 2004 Accessed: Fri Dec 17 13:54:08 2004 Attributes: Type: $STANDARD_INFORMATION (16-0) Name: N/A Resident size: 72 Type: $FILE_NAME (48-2) Name: N/A Resident size: 80 Type: $INDEX_ROOT (144-1) Name: $I30 Resident size: 680 Sleuthkit 3.00: istat for parent folder: ./istat /dev/sdb1 25442 MFT Entry Header Values: Entry: 25442 Sequence: 1 $LogFile Sequence Number: 16787693 Allocated Directory Links: 1 $STANDARD_INFORMATION Attribute Values: Flags: Archive Owner ID: 0 Created: Fri Dec 17 13:50:43 2004 File Modified: Fri Dec 17 13:54:38 2004 MFT Modified: Fri Dec 17 13:54:38 2004 Accessed: Tue Oct 28 14:17:49 2008 $FILE_NAME Attribute Values: Flags: Directory, Archive Name: I386 Parent MFT Entry: 2385 Sequence: 2408 Allocated Size: 0 Actual Size: 0 Created: Fri Dec 17 13:50:43 2004 File Modified: Fri Dec 17 13:54:38 2004 MFT Modified: Fri Dec 17 13:54:38 2004 Accessed: Fri Dec 17 13:54:38 2004 $ATTRIBUTE_LIST Attribute Values: Type: 16-0 MFT Entry: 25442 VCN: 0 Type: 48-2 MFT Entry: 25442 VCN: 0 Type: 144-9 MFT Entry: 25442 VCN: 0 Type: 160-1 MFT Entry: 27750 VCN: 0 Type: 160-11 MFT Entry: 25442 VCN: 1616 Type: 176-10 MFT Entry: 25442 VCN: 0 Attributes: Type: $STANDARD_INFORMATION (16-0) Name: N/A Resident size: 72 Type: $ATTRIBUTE_LIST (32-12) Name: N/A Resident size: 224 Type: $FILE_NAME (48-2) Name: N/A Resident size: 74 Type: $INDEX_ROOT (144-9) Name: $I30 Resident size: 56 Type: $INDEX_ALLOCATION (160-11) Name: $I30 Non-Resident size: 921600 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 9226806 9226807 9226808 9226809 9226810 9226811 9226812 9226813 8279563 8279564 8279565 8279566 8279567 8279568 8279569 8279570 8279583 8279584 8279585 8279586 8279587 8279588 8279589 8279590 562606 562607 562608 562609 562610 562611 562612 562613 4975729 4975730 4975731 4975732 4975733 4975734 4975735 4975736 5201957 5201958 5201959 5201960 5201961 5201962 5201963 5201964 6230377 6230378 6230379 6230380 6230381 6230382 6230383 6230384 6474510 6474511 6474512 6474513 6474514 6474515 6474516 6474517 6474518 6474519 6474520 6474521 6474522 6474523 6474524 6474525 6474769 6474770 6474771 6474772 6474773 6474774 6474775 6474776 7386954 7386955 7386956 7386957 7386958 7386959 7386960 7386961 8130144 8130145 8130146 8130147 8130148 8130149 8130150 8130151 8130260 8130261 8130262 8130263 8130264 8130265 8130266 8130267 8435605 8435606 8435607 8435608 8435609 8435610 8435611 8435612 9253264 9253265 9253266 9253267 9253268 9253269 9253270 9253271 12968399 12968400 12968401 12968402 12968403 12968404 12968405 12968406 12968619 12968620 12968621 12968622 12968623 12968624 12968625 12968626 8014380 8014381 8014382 8014383 8014384 8014385 8014386 8014387 4793927 4793928 4793929 4793930 4793931 4793932 4793933 4793934 6718054 6718055 6718056 6718057 6718058 6718059 6718060 6718061 6718701 6718702 6718703 6718704 6718705 6718706 6718707 6718708 6718709 6718710 6718711 6718712 6460765 6460766 6460767 6460768 8137826 8137827 8137828 8137829 8137830 8137831 8137832 8137833 Type: $BITMAP (176-10) Name: $I30 Resident size: 32 Type: $INDEX_ALLOCATION (160-1) Name: $I30 Non-Resident size: 921600 11830897 11830898 11830899 11830900 11830901 11830902 11830903 11830904 6029520 6029521 6029522 6029523 6029524 6029525 6029526 6029527 6029528 7956180 7956181 7956182 7956183 7956184 7956185 7956186 5620477 5620478 5620479 5620480 5620481 5620482 5620483 5620484 6156845 6156846 6156847 6156848 6156849 6156850 6156851 6156852 6156853 6156854 6156855 6156856 13093078 13093079 13093080 13093081 8796948 8796949 8796950 8796951 8796952 8796953 8796954 8796955 8027697 8027698 8027699 8027700 8027701 8027702 8027703 8027704 8027705 8027706 1630032 1630033 1630034 1630035 1630036 1630037 8918311 8918312 8918313 8918314 8918315 8918316 8918317 8918318 11905949 11905950 11905951 11905952 11905953 11905954 11905955 11905956 11935107 11935108 11935109 11935110 11935111 11935112 11935113 11935114 11935451 11935452 11935453 11935454 11935455 11935456 11935457 11935458 7877375 7877376 7877377 7877378 7877379 7877380 7877381 7877382 7877383 7877384 7877385 7877386 12826824 12826825 12826826 12826827 7338851 7338852 7338853 7338854 7338855 7338856 7338857 7338858 7338859 7338860 7338861 7338862 7338863 7338864 7338865 7338866 7338867 7338868 7338869 7338870 7338871 7338872 911045 911046 483475 483476 483477 483478 483479 483480 483481 483482 483483 483484 483485 483486 483487 483488 483489 483490 483491 483492 483493 483494 483495 483496 483497 6200808 8181505 8181506 8181507 8181508 8181509 8181510 8181511 8181512 8181513 8181514 8181515 8181516 8181517 8181518 8181519 8181520 4792800 4792801 4792802 4792803 4792804 4792805 4792806 4792807 12894781 12894782 12894783 12894784 12894785 12894786 12894787 12894788 189926 189927 189928 189929 189930 189931 189932 189933 189934 189935 189936 189937 189938 189939 189940 189941 8495448 8495449 8495450 8495451 8495452 8495453 8495454 8495455 8495456 8495457 5257243 5257244 5257245 5257246 5257247 5257248 1730855 1730856 1730857 1730858 1730859 1730860 1730861 1730862 6255617 6255618 6255619 6255620 6255621 6255622 6255623 6255624 8703778 8703779 8703780 8703781 8703782 8703783 8703784 8703785 8703786 8703787 5249521 5249522 5249523 5249524 5249525 5249526 7429665 7429666 7429667 7429668 7429669 7429670 7429671 7429672 955410 955411 955412 955413 955414 955415 955416 955417 970234 970235 970236 970237 970238 970239 970240 970241 970242 970243 970244 970245 970246 970247 970248 970249 970250 970251 970252 970253 970254 970255 970256 970257 970258 970259 970260 970261 970262 970263 970264 970265 970266 970267 970268 970269 970270 970271 970272 970273 970274 1557599 1557600 1557601 1557602 1557603 1557604 1557605 6034494 6034495 6034496 6034497 6034498 6034499 6034500 6034501 6034502 6034503 6034504 8158321 8158322 8158323 8158324 8158325 8158326 1431535 1431536 1431537 1431538 1431539 1431540 1431541 6295104 6295105 6295106 6295107 6295108 6295109 6295110 6295111 6295112 1603567 1603568 1603569 1603570 1603571 1603572 1603573 4921710 4921711 4921712 4921713 4921714 4921715 4921716 4921717 6584244 6584245 6584246 6584247 6584248 6584249 6584250 6584251 6584410 6584411 6584412 6584413 6584414 6584415 6584416 6584417 6584418 6584419 6584420 6584421 6584422 6584423 6584424 6038872 8025645 8025646 8025647 8025648 8025649 8025650 8025651 8025652 6941873 6941874 6941875 6941876 6941877 6941878 6941879 6941880 6496837 6496838 6496839 6496840 6496841 6496842 6496843 6496844 7114588 7114589 7114590 7114591 7114592 7114593 7114594 7114595 7560642 7560643 7560644 7560645 7560646 7560647 7560648 7560649 7331575 7331576 7331577 7331578 7331579 7331580 7331581 7331582 8083048 8083049 8083050 8083051 8083052 8083053 8083054 8083055 8083056 8083057 8083058 8083059 8083060 8083061 8083062 8083063 8083267 8083268 8083269 8083270 8083271 8083272 8083273 8083274 7377776 7377777 7377778 7377779 7377780 7377781 7377782 7377783 7377784 1661551 1661552 1661553 1661554 1661555 1661556 1661557 8581712 8581713 8581714 8581715 8581716 8581717 8581718 8581719 6560848 6560849 6560850 6560851 6560852 6560853 6560854 6560855 7600800 7600801 7600802 7600803 7600804 7600805 7600806 7600807 7600808 7600809 7600810 424818 424819 424820 424821 424822 424823 424824 436269 436270 436271 436272 436273 436274 436275 1748431 1748432 1748433 1748434 1748435 1748436 1748437 7632690 7632691 7632692 7632693 7632694 7632695 7632696 7632697 7632698 1749727 1749728 1749729 1749730 1749731 1749732 1749733 7627565 7627566 7627567 7627568 7627569 7627570 7627571 7627572 7627573 7627574 7627575 7627576 7627577 7627578 5834854 5834855 6505643 6505644 6505645 6505646 6505647 6505648 6505649 6505650 6506094 6506095 6506096 6506097 6506098 6506099 6506100 6506101 6506102 6506103 6506104 7363444 7363445 7363446 7363447 7363448 9009489 9009490 9009491 9009492 9009493 9009494 9009495 9009496 9009497 9009498 9009499 644210 644211 644212 644213 644214 644215 644216 660561 660562 660563 660564 660565 660566 660567 1408287 1408288 1408289 1408290 1408291 1408292 1408293 13082746 13082747 13082748 13082749 13082750 13082751 13082752 13082753 4973895 4973896 4973897 4973898 4973899 4973900 4973901 4973902 4973903 4973904 4973905 4973906 4973907 4973908 4973909 4973910 5499122 5499123 5499124 5499125 5499126 5499127 5499128 5499129 5686844 5686845 5686846 5686847 5686848 5686849 5686850 5686851 6049242 6049243 6049244 6049245 6049246 6049247 6049248 6049249 6049250 6049251 6049252 6049253 6049254 6049255 6049256 5501192 6251883 6251884 6251885 6251886 6251887 6251888 6251889 6251890 7625262 7625263 7625264 7625265 7625266 7625267 7625268 7625269 8284704 8284705 8284706 8284707 8284708 8284709 8284710 8284711 8284712 8284713 8284714 972343 972344 972345 972346 972347 972348 972349 1015127 1015128 1015129 1015130 1015131 1015132 1015133 1750367 1750368 1750369 1750370 1750371 1750372 1750373 5868453 5868454 5868455 5868456 5868457 5868458 5868459 5868460 8729227 8729228 8729229 8729230 8729231 8729232 8729233 8729234 8139874 8139875 8139876 8139877 8139878 8139879 8139880 8139881 7792415 7792416 7792417 7792418 7792419 7792420 7792421 7792422 7792423 7792424 7792425 7792426 1037517 1037518 1037519 1037520 1037521 1037522 1037523 1037533 1037534 1037535 1037536 1037537 1037538 1037539 1037581 1037582 1037583 1037584 1037585 1037586 1037587 1750719 1750720 1750721 1750722 1750723 1750724 1750725 798615 798616 798617 798618 798619 798620 798621 798622 798623 1750687 1750688 1750689 1750690 1750691 1750692 1750693 8707871 8707872 8707873 8707874 8707875 8707876 8707877 8707878 9031436 9031437 9031438 9031439 9031440 9031441 9031442 9031443 9031507 9031508 9031509 9031510 9031511 9031512 9031513 9031514 9031714 9031715 9031716 9031717 9031718 9031719 9031720 9031721 9031835 9031836 9031837 9031838 9031839 9031840 9031841 9031842 9031893 9031894 9031895 9031896 9031897 9031898 9031899 9031900 9032007 9032008 9032009 9032010 9032011 9032012 9032013 9032014 13069964 13069965 13069966 13069967 13069968 13069969 13069970 13069971 13070040 13070041 13070042 13070043 13070044 13070045 13070046 13070047 6051815 6051816 6051817 6051818 6051819 6051820 6051821 6051822 6071155 6071156 6071157 6071158 6071159 6071160 6071161 6071162 5387047 5387048 5387049 5387050 5387051 5387052 5387053 5387054 4691541 4691542 4691543 4691544 4691545 4691546 4691547 4691548 4691549 4691550 4691551 4691552 13070551 13070552 13070553 13070554 6079186 6079187 6079188 6079189 6079190 6079191 6079192 6079193 6413336 6413337 6413338 6413339 6413340 6413341 6413342 6413343 6413615 6413616 6413617 6413618 6413619 6413620 6413621 6413622 6900908 6900909 6900910 6900911 6900912 6900913 6900914 6900915 6900916 6900917 6900918 6900919 6900920 7346036 7346037 7346038 7346039 7346040 5932790 5932791 5932792 5932793 5932794 5932795 5932796 11827873 11827874 11827875 11827876 11827877 11827878 11827879 6306321 6306322 6306323 6306324 6306325 6306326 6306327 6306328 6092384 6092385 6092386 6092387 6092388 6092389 6092390 6092391 6092392 9401258 9401259 9401260 9401261 9401262 9401263 9401264 12955292 12955293 12955294 12955295 12955296 12955297 12955298 12955299 5112514 5112515 5112516 5112517 5112518 5112519 5112520 5112521 6911569 6911570 6911571 6911572 6911573 6911574 6911575 6911576 7101353 7101354 7101355 7101356 7101357 7101358 7101359 7101360 7101361 7101362 7101363 7101364 7101365 7101366 7101367 7101368 8712977 8712978 8712979 8712980 8712981 8712982 8712983 8712984 5334493 5334494 5334495 5334496 5334497 5334498 5334499 5334500 5334501 5334502 5334503 5334504 8359749 8359750 8359751 8359752 8359753 8359754 6544098 6544099 6544100 6544101 6544102 6544103 6544104 9337407 9337408 9337409 9337410 9337411 9337412 9337413 7552788 7552789 7552790 7552791 7552792 7552793 7552794 7552795 7553437 7553438 7553439 7553440 7553441 7553442 7553443 7553444 7553562 7553563 7553564 7553565 7553566 7553567 7553568 7553569 8792587 8792588 8792589 8792590 8792591 8792592 8792593 8792594 8792746 8792747 8792748 8792749 8792750 8792751 8792752 8792753 9214228 9214229 9214230 9214231 9214232 9214233 9214234 9214235 9214430 9214431 9214432 9214433 9214434 9214435 9214436 9214437 9214514 9214515 9214516 9214517 9214518 9214519 9214520 9214521 1030435 1030436 1030437 1030438 1030439 1030440 1030441 1030442 1030716 1030717 1030718 1030719 1030720 1030721 1030722 1030723 5264752 5264753 5264754 5264755 5264756 5264757 5264758 5264759 5265093 5265094 5265095 5265096 5265097 5265098 5265099 5265100 5265101 5621181 5621182 5621183 5621184 5621185 5621186 5621187 6891679 6891680 6891681 6891682 6891683 6891684 6891685 6891686 6891687 6891688 6891689 6891690 6891691 6891692 6891693 6891694 8104855 8104856 8104857 8104858 8104859 8104860 8104861 8104862 8104863 8104864 8104865 8104866 8104867 8104868 8104869 8104870 5227582 5227583 5227584 5227585 5227586 5227587 5227588 5227589 5227590 5227591 5227592 5227593 518818 518819 518820 518821 5375875 5375876 5375877 5375878 5375879 5375880 5375881 5375882 5403195 5403196 5403197 5403198 5403199 5403200 5403201 5403202 5403203 5403204 5403205 5403206 5403207 5403208 5403209 5403210 6064004 6064005 6064006 6064007 6064008 6064009 6064010 6064011 6179671 6179672 6179673 6179674 6179675 6179676 6179677 6179678 6315651 6315652 6315653 6315654 6315655 6315656 6315657 6315658 6705103 6705104 6705105 6705106 6705107 6705108 6705109 6705110 6705317 6705318 6705319 6705320 6705321 6705322 6705323 6705324 7744529 7744530 7744531 7744532 7744533 7744534 7744535 7744536 7745137 7745138 7745139 7745140 7745141 7745142 7745143 7745144 7903260 7903261 7903262 7903263 7903264 7903265 7903266 7903267 7968689 7968690 7968691 7968692 7968693 7968694 7968695 7968696 8113815 8113816 8113817 8113818 8113819 8113820 8113821 8113822 8539299 8539300 8539301 8539302 8539303 8539304 8539305 8539306 8572209 8572210 8572211 8572212 8572213 8572214 8572215 8572216 12760230 12760231 12760232 12760233 12760234 12760235 12760236 12760237 517148 517149 517150 517151 517152 517153 517154 517155 517367 517368 517369 517370 517371 517372 517373 517374 768822 768823 768824 768825 768826 768827 768828 768829 6071580 6071581 6071582 6071583 6071584 6071585 6071586 6071587 6072178 6072179 6072180 6072181 6072182 6072183 6072184 6072185 7001616 7001617 7001618 7001619 7001620 7001621 7001622 7001623 8400304 8400305 8400306 8400307 8400308 8400309 8400310 8400311 8400659 8400660 8400661 8400662 8400663 8400664 8400665 8400666 6210287 6210288 6210289 6210290 6210291 6210292 6210293 6210294 6212587 6212588 6212589 6212590 6212591 6212592 6212593 6212594 7567875 7567876 7567877 7567878 7567879 7567880 7567881 7567882 7531829 7531830 7531831 7531832 7531833 7531834 7531835 7531836 7531837 7531838 7531839 7531840 7531841 7531842 7531843 7531844 7531887 7531888 7531889 7531890 7531891 7531892 7531893 7531894 7206226 7206227 7206228 7206229 7206230 7206231 7206232 7206233 7206767 7206768 7206769 7206770 7206771 7206772 7206773 7206774 7206775 7206776 8049832 8049833 8049834 8049835 8049836 8049837 4987819 4987820 4987821 4987822 4987823 4987824 4987825 4987826 4988328 4988329 4988330 4988331 4988332 4988333 4988334 4988335 6074929 6074930 6074931 6074932 6074933 6074934 6074935 6074936 6075275 6075276 6075277 6075278 6075279 6075280 6075281 6075282 6075283 6075284 6075285 6075286 6075287 6075288 185018 185019 9087980 9087981 9087982 9087983 9087984 9087985 9087986 9087987 9088043 9088044 9088045 9088046 9088047 9088048 9088049 9088050 13112758 13112759 13112760 13112761 13112762 13112763 13112764 13112765 6744132 6744133 6744134 6744135 6744136 6744137 6744138 6744139 7639596 7639597 7639598 7639599 7639600 7639601 7639602 7639603 8715965 8715966 8715967 8715968 8715969 8715970 8715971 8715972 6073220 6073221 6073222 6073223 6073224 6073225 6073226 6073227 7208816 7208817 7208818 7208819 7208820 7208821 7208822 7208823 7208824 225944 225945 225946 225947 225948 225949 225950 9226706 9226707 9226708 9226709 9226710 9226711 9226712 9226713 istat for missing folder: ./istat /dev/sdb1 30211 MFT Entry Header Values: Entry: 30211 Sequence: 1 $LogFile Sequence Number: 16790486 Allocated Directory Links: 1 $STANDARD_INFORMATION Attribute Values: Flags: Archive Owner ID: 0 Created: Fri Dec 17 13:54:08 2004 File Modified: Fri Dec 17 13:54:08 2004 MFT Modified: Fri Dec 17 13:54:08 2004 Accessed: Tue Oct 28 14:18:01 2008 $FILE_NAME Attribute Values: Flags: Directory, Archive Name: UNIPROC Parent MFT Entry: 25442 Sequence: 1 Allocated Size: 0 Actual Size: 0 Created: Fri Dec 17 13:54:08 2004 File Modified: Fri Dec 17 13:54:08 2004 MFT Modified: Fri Dec 17 13:54:08 2004 Accessed: Fri Dec 17 13:54:08 2004 Attributes: Type: $STANDARD_INFORMATION (16-0) Name: N/A Resident size: 72 Type: $FILE_NAME (48-2) Name: N/A Resident size: 80 Type: $INDEX_ROOT (144-1) Name: $I30 Resident size: 680 ---------------------------------------------------------------------- You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=477889&aid=2490550&group_id=55685 |
From: SourceForge.net <no...@so...> - 2008-12-30 02:03:38
|
Bugs item #2389901, was opened at 2008-12-04 13:02 Message generated for change (Comment added) made by carrier You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=477889&aid=2389901&group_id=55685 Please note that this message will contain a full copy of the comment thread, including the initial issue submission, for this request, not just the latest update. Category: File System Tools Group: None >Status: Closed >Resolution: Fixed Priority: 5 Private: No Submitted By: Brian Carrier (carrier) Assigned to: Brian Carrier (carrier) Summary: Deleted NTFS files should have "unknown" type in file name Initial Comment: The deleted NTFS files that are found by searching for entries for a given parent directory should have an "unknown" for the file type as identified in the file name structure (because the file name structure was not analyzed). This is the behavior that 'ifind -p' currently uses and 'fls' should as well for consistency. For example: # fls -Frd -o 59 ntfs_pract.dd ... r/r * 112-128-4: My Documents/My Pictures/bandit-streetortrack2005056.jpg # ifind -p 110 -o 59 ntfs_pract.dd -/r * 112-128-4: bandit-streetortrack2005056.jpg Reported by Barry Grundy. ---------------------------------------------------------------------- >Comment By: Brian Carrier (carrier) Date: 2008-12-29 20:57 Message: Fixed for both orphan files and NTFS files that are found via parent directory. Checked into trunk and branches/3.0. ---------------------------------------------------------------------- You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=477889&aid=2389901&group_id=55685 |
From: SourceForge.net <no...@so...> - 2008-12-29 18:11:42
|
Bugs item #2475246, was opened at 2008-12-29 12:46 Message generated for change (Comment added) made by carrier You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=477889&aid=2475246&group_id=55685 Please note that this message will contain a full copy of the comment thread, including the initial issue submission, for this request, not just the latest update. Category: File System Tools Group: None >Status: Closed >Resolution: Fixed Priority: 5 Private: No Submitted By: Brian Carrier (carrier) Assigned to: Brian Carrier (carrier) Summary: istat not showing ExtX sparse blocks Initial Comment: Reported by Simson Garfinkel: You can download the scan from http://old.honeynet.org/scans/scan15/ 12:52 PM m:~/honeynet$ istat honeypot.hda8.dd 56231 inode: 56231 Not Allocated Group: 28 Generation Id: 2386177400 uid / gid: 0 / 0 mode: rrw-r--r-- size: 33135 num of links: 0 Inode Times: Accessed: Thu Mar 15 03:17:36 2001 File Modified: Thu Mar 15 03:17:36 2001 Inode Modified: Thu Mar 15 03:17:36 2001 Deleted: Thu Mar 15 03:17:36 2001 Direct Blocks: 229685 229686 229687 229688 229689 229690 229691 229692 229693 229694 229695 229696 There should be several zeros after this. ---------------------------------------------------------------------- >Comment By: Brian Carrier (carrier) Date: 2008-12-29 13:11 Message: Fixed in 3.0 and trunk by properly setting _CONT flag in sparse blocks for Ext and FFS. Sending fs/ext2fs.c Sending fs/ffs.c Sending fs/fs_attr.c Sending fs/tsk_fs.h Transmitting file data .... Committed revision 34. Also in 32 and 33. ---------------------------------------------------------------------- You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=477889&aid=2475246&group_id=55685 |
From: SourceForge.net <no...@so...> - 2008-12-29 17:46:41
|
Bugs item #2475246, was opened at 2008-12-29 12:46 Message generated for change (Tracker Item Submitted) made by Item Submitter You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=477889&aid=2475246&group_id=55685 Please note that this message will contain a full copy of the comment thread, including the initial issue submission, for this request, not just the latest update. Category: File System Tools Group: None Status: Open Resolution: None Priority: 5 Private: No Submitted By: Brian Carrier (carrier) Assigned to: Brian Carrier (carrier) Summary: istat not showing ExtX sparse blocks Initial Comment: Reported by Simson Garfinkel: You can download the scan from http://old.honeynet.org/scans/scan15/ 12:52 PM m:~/honeynet$ istat honeypot.hda8.dd 56231 inode: 56231 Not Allocated Group: 28 Generation Id: 2386177400 uid / gid: 0 / 0 mode: rrw-r--r-- size: 33135 num of links: 0 Inode Times: Accessed: Thu Mar 15 03:17:36 2001 File Modified: Thu Mar 15 03:17:36 2001 Inode Modified: Thu Mar 15 03:17:36 2001 Deleted: Thu Mar 15 03:17:36 2001 Direct Blocks: 229685 229686 229687 229688 229689 229690 229691 229692 229693 229694 229695 229696 There should be several zeros after this. ---------------------------------------------------------------------- You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=477889&aid=2475246&group_id=55685 |
From: SourceForge.net <no...@so...> - 2008-12-13 23:04:23
|
Feature Requests item #2424611, was opened at 2008-12-13 18:04 Message generated for change (Tracker Item Submitted) made by Item Submitter You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=477892&aid=2424611&group_id=55685 Please note that this message will contain a full copy of the comment thread, including the initial issue submission, for this request, not just the latest update. Category: File System Group: None Status: Open Priority: 5 Private: No Submitted By: Brian Carrier (carrier) Assigned to: Nobody/Anonymous (nobody) Summary: Ability to output MFT entry slack space Initial Comment: MFT entries are a fixed size and there could be unused space at the end that contains relevant data. Provide a way to access it. This could use a special attribute so that 'icat' can be used to output it. ---------------------------------------------------------------------- You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=477892&aid=2424611&group_id=55685 |
From: SourceForge.net <no...@so...> - 2008-12-12 15:16:26
|
Feature Requests item #2421421, was opened at 2008-12-12 10:16 Message generated for change (Tracker Item Submitted) made by Item Submitter You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=477900&aid=2421421&group_id=55687 Please note that this message will contain a full copy of the comment thread, including the initial issue submission, for this request, not just the latest update. Category: Analysis Techniques Group: None Status: Open Priority: 5 Private: No Submitted By: Brian Carrier (carrier) Assigned to: Nobody/Anonymous (nobody) Summary: Logical keyword searching Initial Comment: Support logical keyword searching instead of physical so that the contents of compressed NTFS files and strings that cross fragmented blocks can be found. ---------------------------------------------------------------------- You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=477900&aid=2421421&group_id=55687 |
From: SourceForge.net <no...@so...> - 2008-12-06 03:00:05
|
Feature Requests item #2394013, was opened at 2008-12-05 22:00 Message generated for change (Tracker Item Submitted) made by Item Submitter You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=477892&aid=2394013&group_id=55685 Please note that this message will contain a full copy of the comment thread, including the initial issue submission, for this request, not just the latest update. Category: File System Group: None Status: Open Priority: 5 Private: No Submitted By: Brian Carrier (carrier) Assigned to: Nobody/Anonymous (nobody) Summary: Scan for MFT entries in unallocated space Initial Comment: If an NTFS drive is formatted, there could be MFT entries in unallocated space that could describe the layout of files. TSK should be scanning for them. ---------------------------------------------------------------------- You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=477892&aid=2394013&group_id=55685 |
From: SourceForge.net <no...@so...> - 2008-12-04 18:02:18
|
Bugs item #2389901, was opened at 2008-12-04 13:02 Message generated for change (Tracker Item Submitted) made by Item Submitter You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=477889&aid=2389901&group_id=55685 Please note that this message will contain a full copy of the comment thread, including the initial issue submission, for this request, not just the latest update. Category: File System Tools Group: None Status: Open Resolution: None Priority: 5 Private: No Submitted By: Brian Carrier (carrier) Assigned to: Brian Carrier (carrier) Summary: Deleted NTFS files should have "unknown" type in file name Initial Comment: The deleted NTFS files that are found by searching for entries for a given parent directory should have an "unknown" for the file type as identified in the file name structure (because the file name structure was not analyzed). This is the behavior that 'ifind -p' currently uses and 'fls' should as well for consistency. For example: # fls -Frd -o 59 ntfs_pract.dd ... r/r * 112-128-4: My Documents/My Pictures/bandit-streetortrack2005056.jpg # ifind -p 110 -o 59 ntfs_pract.dd -/r * 112-128-4: bandit-streetortrack2005056.jpg Reported by Barry Grundy. ---------------------------------------------------------------------- You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=477889&aid=2389901&group_id=55685 |
From: Jon W. <jw...@op...> - 2008-11-27 05:28:16
|
I'll chip in with another thumbs up. I feel this would make my testing much easier. RB wrote: > How about a strong opinion for? |
From: RB <ao...@gm...> - 2008-11-26 17:28:22
|
On Wed, Nov 26, 2008 at 09:54, Brian Carrier <ca...@sl...> wrote: > that setting). Before I do that, anyone with strong opinions on why > I shouldn't do it (since most open source projects seem to use this > technique)? How about a strong opinion for? Email is so much nicer than a poll-only interface like an HTTP interface. I can read and digest much more in bulk offline at my own pace, particularly since I'm out of connection range a lot of the time. RB |
From: Brian C. <ca...@sl...> - 2008-11-26 16:54:58
|
For the past couple of years, I stopped using the bug and feature request trackers on sourceforge. I'm now going to start using them again (and stop using the TODO file) so that people can more easily find out what needs to be / can be done. My plan is to configure the trackers to send e-mail to this list when new bugs / feature requests are added (I'll finish the upload of my TODO list before I enable that setting). Before I do that, anyone with strong opinions on why I shouldn't do it (since most open source projects seem to use this technique)? FYI, links to the trackers can be found here: http://wiki.sleuthkit.org/index.php?title=Trackers thanks, brian |
From: Brian C. <ca...@sl...> - 2008-11-13 19:47:48
|
It looks like the result that TSK got from the system was 0x0FFFFFFF and it subtracted one to get the 268435454 number. That is an error code that was not caught... Is there anyone interested in taking a lead on the disktools? They are fairly independent from the rest of the code base and I have not had the time to devote any attention to them. Or, if no one wants to look at fixing some of these problems and hdparm provides all of the needed data then perhaps disktools should just be abandoned. brian On Nov 12, 2008, at 6:40 PM, Ade wrote: > Just something I thought might be of interest to the group. The > newest > version of hdparm has some interesting developments. >> From http://freshmeat.net/projects/hdparm/? >> branch_id=4062&release_id=288158: > > *"Changes:* > Support for Device Configuration Overlay was added, with the new flags > "--dco-freeze", "--dco-identify", and "--dco-restore"." > > I have compared results from disk_stat with hdparm --dco-identify > command on my home machine. On my main O/S drive disk_stat > reports one > less sector than hdparm, I guess that disk_stat is counting from zero > and hdparm counting from one. > > On my storage drive, something curious occurs: > hdparm --dco-identify reports "Real max sectors" as 488397168 > > Disk_stat on the same disk gives the following output: > Maximum Disk Sector: 268435454 > Maximum User Sector: 488397167 > > Again, there is one sector difference between the max number of > sectors > reported by disk_stat and hdparm, but I don't understand how the > Maximum > User Sectors can be larger than the Maximum Disk Sectors. If I > understood Issue #20 of the sleuthkit Informer correctly, the Maximum > User Sector is the number of sectors visible to the user, the Maximum > Disk Sector is the Maximum User Sector + the number of sectors in the > HPA. Can anyone explain the disk_stat output above? I am using > disk_stat version 3.0.0b3 > > Thanks > > Adrian Shaw > > > > > ---------------------------------------------------------------------- > --- > This SF.Net email is sponsored by the Moblin Your Move Developer's > challenge > Build the coolest Linux based applications with Moblin SDK & win > great prizes > Grand prize is a trip for two to an Open Source event anywhere in > the world > http://moblin-contest.org/redirect.php?banner_id=100&url=/ > _______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org |
From: Brian C. <ca...@sl...> - 2008-10-29 14:56:28
|
On Oct 29, 2008, at 9:56 AM, Christophe GRENIER wrote: > On Wed, 29 Oct 2008, Brian Carrier wrote: > >> Hi Christophe, >> >> Thanks, but that didn't seem to change anything on my XP system >> when trying to open \\.\PhysicalDrive0. I still get a sharing >> violation. >> >>> So far, it works well under Vista as long as you run TestDisk >>> using right-click "Run as Administrator". >> >> It works on both \\.\C: and \\.\PhysicalDrive0? > > Hi Brian, > > TestDisk opens both but by default, it won't display C: if > PhysicalDrive0 has worked unless "testdisk /all" is used. > Does TestDisk work on your system ? It does, but it reports it as /dev/sda. Is it actually using /dev/ sda or is it mapping to \\.\PhysicalDrive0 behind the scenes? > Is there another program already accessing \\.\PhysicalDrive0? > It may explain the sharing violation. Could be. Although, I seem to be able to open \\.\PhysicalDrive0 from within Cygwin without error (although TSK is not getting the correct size of the device through Cygwin...). thanks, brian |
From: Christophe G. <gr...@cg...> - 2008-10-29 13:56:31
|
On Wed, 29 Oct 2008, Brian Carrier wrote: > Hi Christophe, > > Thanks, but that didn't seem to change anything on my XP system when trying > to open \\.\PhysicalDrive0. I still get a sharing violation. > >> So far, it works well under Vista as long as you run TestDisk >> using right-click "Run as Administrator". > > It works on both \\.\C: and \\.\PhysicalDrive0? Hi Brian, TestDisk opens both but by default, it won't display C: if PhysicalDrive0 has worked unless "testdisk /all" is used. Does TestDisk work on your system ? Is there another program already accessing \\.\PhysicalDrive0? It may explain the sharing violation. Christophe -- ,-~~-.___. ._. / | ' \ | |--------. Christophe GRENIER ( ) 0 | | | gr...@cg... \_/-, ,----' | | | ==== !_!-v---v--. / \-'~; .--------. TestDisk & PhotoRec / __/~| ._-""|| | Data Recovery =( _____|_|____||________| http://www.cgsecurity.org |
From: Brian C. <ca...@sl...> - 2008-10-29 13:27:05
|
On Oct 29, 2008, at 3:12 AM, Christophe GRENIER wrote: > On Tue, 28 Oct 2008, Brian Carrier wrote: > >> Hi Michael, >> >> I only want read access, but I tried adding GENERIC_WRITE and it >> still failed. >> >> I recently added the FILE_SHARE_WRITE because someone reported that >> it was needed when the device has already been opened with write >> access because I am then willing to "share" the device with that >> program. >> >> I don't get the sharing violation when I use \\.\C: though, so >> perhaps the CreateFile arguments are correct and it is simply that >> PhysicalDrive0 is opened and not being shared. > >>> device_handle = CreateFileA(image, GENERIC_READ | GENERIC_WRITE, >>> FILE_SHARE_READ | FILE_SHARE_WRITE, >>> NULL, OPEN_EXISTING, 0, NULL); > > Hello, > > Windows version of TestDisk is using > device_handle = CreateFileA(image, FILE_READ_DATA | FILE_WRITE_DATA, > FILE_SHARE_READ | FILE_SHARE_WRITE, > NULL, OPEN_EXISTING, 0, NULL); > > FILE_READ_DATA requires less privileges than GENERIC_READ, > see http://msdn.microsoft.com/fr-fr/aa364399(en-us).aspx Hi Christophe, Thanks, but that didn't seem to change anything on my XP system when trying to open \\.\PhysicalDrive0. I still get a sharing violation. > So far, it works well under Vista as long as you run TestDisk > using right-click "Run as Administrator". It works on both \\.\C: and \\.\PhysicalDrive0? thanks, brian |
From: Michele Z. <mi...@ya...> - 2008-10-29 09:53:47
|
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html><head><title></title> <META http-equiv=Content-Type content="text/html; charset=iso-8859-1"> <meta http-equiv="Content-Style-Type" content="text/css"> <style type="text/css"><!-- body { margin: 5px 5px 5px 5px; background-color: #ffffff; } /* ========== Text Styles ========== */ hr { color: #000000} body, table /* Normal text */ { font-size: 9pt; font-family: 'Courier New'; font-style: normal; font-weight: normal; color: #000000; text-decoration: none; } span.rvts1 /* Heading */ { font-size: 10pt; font-family: 'Arial'; font-weight: bold; color: #0000ff; } span.rvts2 /* Subheading */ { font-size: 10pt; font-family: 'Arial'; font-weight: bold; color: #000080; } span.rvts3 /* Keywords */ { font-size: 10pt; font-family: 'Arial'; font-style: italic; color: #800000; } a.rvts4, span.rvts4 /* Jump 1 */ { font-size: 10pt; font-family: 'Arial'; color: #008000; text-decoration: underline; } a.rvts5, span.rvts5 /* Jump 2 */ { font-size: 10pt; font-family: 'Arial'; color: #008000; text-decoration: underline; } span.rvts6 { font-size: 11pt; font-family: 'tahoma'; font-weight: bold; color: #ffffff; background-color: #0000ff; } span.rvts7 { font-size: 11pt; font-family: 'tahoma'; } a.rvts8, span.rvts8 { font-size: 11pt; font-family: 'tahoma'; color: #0000ff; text-decoration: underline; } a.rvts9, span.rvts9 { color: #0000ff; text-decoration: underline; } a.rvts10, span.rvts10 { color: #0000ff; text-decoration: underline; } /* ========== Para Styles ========== */ p,ul,ol /* Paragraph Style */ { text-align: left; text-indent: 0px; padding: 0px 0px 0px 0px; margin: 0px 0px 0px 0px; } ..rvps1 /* Centered */ { text-align: center; } --></style> </head> <body> <p>Just wanted to Add: PTK Adopt the same Patch submission process of TSK: "Currently, these tools have a Benevolent Dictator model for incorporating code into the official distribution. Acceptance is based on code quality and completeness."</p> <p><br></p> <p>refer to: <a class=rvts10 href="http://wiki.sleuthkit.org/index.php?title=Developer_Guidelines">http://wiki.sleuthkit.org/index.php?title=Developer_Guidelines</a></p> <p><br></p> <p><br></p> <div><table border=0 cellpadding=1 cellspacing=2> <tr valign=top> <td width=12 style="background-color: #0000ff;"> <p><span class=rvts6>></span></p> </td> <td width=831 style="background-color: #ffffff;"> <p><span class=rvts7>Hello RB, </span></p> <p><br></p> <p><span class=rvts7>If i can tell you the truth, i ve read the posts on the PTK Mailing list on SF and i disagree with you. I would suggest you to read the mail you sent to this people and objectively try to put yourself in their shoes. Of course you are free to do whatever you want with your time, but i dont think is fair if you say that you are wasting your time with them and that there is no reason to waste time either (this is what your email says) They are hardly working on the project, they have a mindset (by the way the license model is similar to many others in the forensic field) that could be wrong or right but, i mean: let them work in the way they think is right. Give them suggestions, not drastic comments . I am not their advocate but knowing them (Who knows Dario, also know that he is a great and frendly guy), and having read the email you sent them, i think that if you got such an answer there is a reason. </span></p> <p><span class=rvts7>Anyway, the bottom line is that i don't think people here are interested in these silly things. I use PTK and it works, and it filled a gap in a very good way. Maybe you (and other people like you) should look at it just in this way.</span></p> <p><br></p> <p><span class=rvts7>Best</span></p> <p><br></p> <p><span class=rvts7>Grusso</span></p> <p><br></p> <p><br></p> <p><br></p> <p><br></p> <p><br></p> <p><span class=rvts7>From: RB <</span><a class=rvts8 href="mailto:ao...@gm...">ao...@gm...</a><span class=rvts7>></span></p> <p><span class=rvts7>To: </span><a class=rvts8 href="mailto:sle...@li...">sle...@li...</a><span class=rvts7>, </span><a class=rvts8 href="mailto:vo...@vo...">vo...@vo...</a></p> <p><span class=rvts7>Date: Wednesday, October 29, 2008, 2:46:35 AM</span></p> <p><span class=rvts7>Subject: [sleuthkit-developers] Industrial sabotage</span></p> <p><span class=rvts7> </span></p> <p><span class=rvts7>I have been accused of many ugly things, the least of which are likely</span></p> <p><span class=rvts7>inappropriate for this forum. This is the first time I've been</span></p> <p><span class=rvts7>(obliquely or not) accused of industrial sabotage:</span></p> <p><a class=rvts8 href="http://sourceforge.net/mailarchive/message.php?msg_name=C52BD82E.28F72%25dario.forte%40dflabs.com">http://sourceforge.net/mailarchive/message.php?msg_name=C52BD82E.28F72%25dario.forte%40dflabs.com</a><span class=rvts7>.</span></p> <p><span class=rvts7> For those unfamiliar with the project, it's a new-this-year forensic</span></p> <p><span class=rvts7>front-end based wholly on your software.</span></p> <p><br></p> <p><span class=rvts7>Those few of you who know me know what a farce the accusation is and</span></p> <p><span class=rvts7>that my intent is far from trolling. Even so, for the combined sins</span></p> <p><span class=rvts7>of publicly contesting their license and criticizing their</span></p> <p><span class=rvts7>unwillingness to collaborate, I have both times attracted the [rather</span></p> <p><span class=rvts7>belligerent in my estimation] attention of the sponsoring company's</span></p> <p><span class=rvts7>founder and have now been blacklisted from the project. I therefore</span></p> <p><span class=rvts7>am evidently a troll and have someone's friends in NYC that would be</span></p> <p><span class=rvts7>more harsh with me. [thisjustin: One of my new short-term goals is to</span></p> <p><span class=rvts7>avoid both Italy and NYC.]</span></p> <p><br></p> <p><span class=rvts7>I wish PTK the best of fortune; they are doing some very interesting</span></p> <p><span class=rvts7>things and my only desire was to be of assistance. It is unfortunate</span></p> <p><span class=rvts7>that the discussion was made personal; I had no intent to allow it to</span></p> <p><span class=rvts7>become so, but it seems the only option to avoid that was to simply</span></p> <p><span class=rvts7>not interact. I do expect an... agitated... response from the same</span></p> <p><span class=rvts7>party, but will not pollute your lists further with this petty tiff;</span></p> <p><span class=rvts7>my only intent in mass-posting was to make record of the truth and</span></p> <p><span class=rvts7>raise awareness of an interesting new project that thus far only seems</span></p> <p><span class=rvts7>to have gotten its meatspace interface wrong.</span></p> <p><br></p> <p><span class=rvts7>Thanks for all the fish (but not 'so long')!</span></p> <p><br></p> <p><br></p> <p><span class=rvts7>RB</span></p> <p><br></p> <p><span class=rvts7>-------------------------------------------------------------------------</span></p> <p><span class=rvts7>This SF.Net email is sponsored by the Moblin Your Move Developer's challenge</span></p> <p><span class=rvts7>Build the coolest Linux based applications with Moblin SDK & win great prizes</span></p> <p><span class=rvts7>Grand prize is a trip for two to an Open Source event anywhere in the world</span></p> <p><a class=rvts8 href="http://moblin-contest.org/redirect.php?banner_id=100&url=/">http://moblin-contest.org/redirect.php?banner_id=100&url=/</a></p> <p><span class=rvts7>_______________________________________________</span></p> <p><span class=rvts7>sleuthkit-developers mailing list</span></p> <p><a class=rvts8 href="mailto:sle...@li...">sle...@li...</a></p> <p><a class=rvts8 href="https://lists.sourceforge.net/lists/listinfo/sleuthkit-developers">https://lists.sourceforge.net/lists/listinfo/sleuthkit-developers</a></p> </td> </tr> </table> </div> <p><br></p> <p><br></p> <p><br></p> <p><br></p> <p>________________</p> <p>Michele Zambelli </p> <p><a class=rvts9 href="mailto:mi...@ya...">mailto:mi...@ya...</a> </p> </body></html> Chiacchiera con i tuoi amici in tempo reale! http://it.yahoo.com/mail_it/foot/*http://it.messenger.yahoo.com |
From: Giuliano r. <rus...@gm...> - 2008-10-29 09:41:39
|
Hello RB, If i can tell you the truth, i ve read the posts on the PTK Mailing list on SF and i disagree with you. I would suggest you to read the mail you sent to this people and objectively try to put yourself in their shoes. Of course you are free to do whatever you want with your time, but i dont think is fair if you say that you are wasting your time with them and that there is no reason to waste time either (this is what your email says) They are hardly working on the project, they have a mindset (by the way the license model is similar to many others in the forensic field) that could be wrong or right but, i mean: let them work in the way they think is right. Give them suggestions, not drastic comments . I am not their advocate but knowing them (Who knows Dario, also know that he is a great and frendly guy), and having read the email you sent them, i think that if you got such an answer there is a reason. Anyway, the bottom line is that i don't think people here are interested in these silly things. I use PTK and it works, and it filled a gap in a very good way. Maybe you (and other people like you) should look at it just in this way. Best Grusso From: RB <ao...@gm...> To: sle...@li..., vo...@vo... Date: Wednesday, October 29, 2008, 2:46:35 AM Subject: [sleuthkit-developers] Industrial sabotage I have been accused of many ugly things, the least of which are likely inappropriate for this forum. This is the first time I've been (obliquely or not) accused of industrial sabotage: http://sourceforge.net/mailarchive/message.php?msg_name=C52BD82E.28F72%25dario.forte%40dflabs.com . For those unfamiliar with the project, it's a new-this-year forensic front-end based wholly on your software. Those few of you who know me know what a farce the accusation is and that my intent is far from trolling. Even so, for the combined sins of publicly contesting their license and criticizing their unwillingness to collaborate, I have both times attracted the [rather belligerent in my estimation] attention of the sponsoring company's founder and have now been blacklisted from the project. I therefore am evidently a troll and have someone's friends in NYC that would be more harsh with me. [thisjustin: One of my new short-term goals is to avoid both Italy and NYC.] I wish PTK the best of fortune; they are doing some very interesting things and my only desire was to be of assistance. It is unfortunate that the discussion was made personal; I had no intent to allow it to become so, but it seems the only option to avoid that was to simply not interact. I do expect an... agitated... response from the same party, but will not pollute your lists further with this petty tiff; my only intent in mass-posting was to make record of the truth and raise awareness of an interesting new project that thus far only seems to have gotten its meatspace interface wrong. Thanks for all the fish (but not 'so long')! RB ------------------------------------------------------------------------- This SF.Net email is sponsored by the Moblin Your Move Developer's challenge Build the coolest Linux based applications with Moblin SDK & win great prizes Grand prize is a trip for two to an Open Source event anywhere in the world http://moblin-contest.org/redirect.php?banner_id=100&url=/ _______________________________________________ sleuthkit-developers mailing list sle...@li... https://lists.sourceforge.net/lists/listinfo/sleuthkit-developers |
From: Christophe G. <gr...@cg...> - 2008-10-29 07:35:18
|
On Tue, 28 Oct 2008, Brian Carrier wrote: > Hi Michael, > > I only want read access, but I tried adding GENERIC_WRITE and it > still failed. > > I recently added the FILE_SHARE_WRITE because someone reported that > it was needed when the device has already been opened with write > access because I am then willing to "share" the device with that > program. > > I don't get the sharing violation when I use \\.\C: though, so > perhaps the CreateFile arguments are correct and it is simply that > PhysicalDrive0 is opened and not being shared. >> device_handle = CreateFileA(image, GENERIC_READ | GENERIC_WRITE, >> FILE_SHARE_READ | FILE_SHARE_WRITE, >> NULL, OPEN_EXISTING, 0, NULL); Hello, Windows version of TestDisk is using device_handle = CreateFileA(image, FILE_READ_DATA | FILE_WRITE_DATA, FILE_SHARE_READ | FILE_SHARE_WRITE, NULL, OPEN_EXISTING, 0, NULL); FILE_READ_DATA requires less privileges than GENERIC_READ, see http://msdn.microsoft.com/fr-fr/aa364399(en-us).aspx So far, it works well under Vista as long as you run TestDisk using right-click "Run as Administrator". Regards, Christophe -- ,-~~-.___. ._. / | ' \ | |--------. Christophe GRENIER ( ) 0 | | | gr...@cg... \_/-, ,----' | | | ==== !_!-v---v--. / \-'~; .--------. TestDisk & PhotoRec / __/~| ._-""|| | Data Recovery =( _____|_|____||________| http://www.cgsecurity.org |
From: RB <ao...@gm...> - 2008-10-29 01:46:40
|
I have been accused of many ugly things, the least of which are likely inappropriate for this forum. This is the first time I've been (obliquely or not) accused of industrial sabotage: http://sourceforge.net/mailarchive/message.php?msg_name=C52BD82E.28F72%25dario.forte%40dflabs.com. For those unfamiliar with the project, it's a new-this-year forensic front-end based wholly on your software. Those few of you who know me know what a farce the accusation is and that my intent is far from trolling. Even so, for the combined sins of publicly contesting their license and criticizing their unwillingness to collaborate, I have both times attracted the [rather belligerent in my estimation] attention of the sponsoring company's founder and have now been blacklisted from the project. I therefore am evidently a troll and have someone's friends in NYC that would be more harsh with me. [thisjustin: One of my new short-term goals is to avoid both Italy and NYC.] I wish PTK the best of fortune; they are doing some very interesting things and my only desire was to be of assistance. It is unfortunate that the discussion was made personal; I had no intent to allow it to become so, but it seems the only option to avoid that was to simply not interact. I do expect an... agitated... response from the same party, but will not pollute your lists further with this petty tiff; my only intent in mass-posting was to make record of the truth and raise awareness of an interesting new project that thus far only seems to have gotten its meatspace interface wrong. Thanks for all the fish (but not 'so long')! RB |
From: Brian C. <ca...@sl...> - 2008-10-28 14:13:37
|
Hi Michael, I only want read access, but I tried adding GENERIC_WRITE and it still failed. I recently added the FILE_SHARE_WRITE because someone reported that it was needed when the device has already been opened with write access because I am then willing to "share" the device with that program. I don't get the sharing violation when I use \\.\C: though, so perhaps the CreateFile arguments are correct and it is simply that PhysicalDrive0 is opened and not being shared. thanks, brian On Oct 27, 2008, at 7:52 PM, Michael Cohen wrote: > Hi Brian, > > I normally do this: > > device_handle = CreateFileA(image, GENERIC_READ | GENERIC_WRITE, > FILE_SHARE_READ | FILE_SHARE_WRITE, > NULL, OPEN_EXISTING, 0, NULL); > > To get write access to the raw device. Im not sure what it means to > specify FILE_SHARE_WRITE without specifying GENERIC_WRITE. The code > that I got it from was running fine on WinXP - not tested on Vista. > Why would sk need to open with FILE_SHARE_WRITE anyway? > > It may also be possible that another program has the raw device > already open for writing without sharing permitted. > > Hope this helps, > > Michael. > > On Tue, Oct 28, 2008 at 4:46 AM, Brian Carrier > <ca...@sl...> wrote: >> Any win32 developers know why TSK is getting a sharing error (0x20) >> with this statement: >> >> raw_info->fd = CreateFile(image, GENERIC_READ, >> FILE_SHARE_READ | FILE_SHARE_WRITE, 0, >> OPEN_EXISTING, 0, 0); >> >> when trying to open "\\.\PhysicalDrive0" ? >> >> >> --------------------------------------------------------------------- >> ---- >> This SF.Net email is sponsored by the Moblin Your Move Developer's >> challenge >> Build the coolest Linux based applications with Moblin SDK & win >> great prizes >> Grand prize is a trip for two to an Open Source event anywhere in >> the world >> http://moblin-contest.org/redirect.php?banner_id=100&url=/ >> _______________________________________________ >> sleuthkit-developers mailing list >> sle...@li... >> https://lists.sourceforge.net/lists/listinfo/sleuthkit-developers >> |
From: Michael C. <scu...@gm...> - 2008-10-27 23:52:43
|
Hi Brian, I normally do this: device_handle = CreateFileA(image, GENERIC_READ | GENERIC_WRITE, FILE_SHARE_READ | FILE_SHARE_WRITE, NULL, OPEN_EXISTING, 0, NULL); To get write access to the raw device. Im not sure what it means to specify FILE_SHARE_WRITE without specifying GENERIC_WRITE. The code that I got it from was running fine on WinXP - not tested on Vista. Why would sk need to open with FILE_SHARE_WRITE anyway? It may also be possible that another program has the raw device already open for writing without sharing permitted. Hope this helps, Michael. On Tue, Oct 28, 2008 at 4:46 AM, Brian Carrier <ca...@sl...> wrote: > Any win32 developers know why TSK is getting a sharing error (0x20) > with this statement: > > raw_info->fd = CreateFile(image, GENERIC_READ, > FILE_SHARE_READ | FILE_SHARE_WRITE, 0, > OPEN_EXISTING, 0, 0); > > when trying to open "\\.\PhysicalDrive0" ? > > > ------------------------------------------------------------------------- > This SF.Net email is sponsored by the Moblin Your Move Developer's challenge > Build the coolest Linux based applications with Moblin SDK & win great prizes > Grand prize is a trip for two to an Open Source event anywhere in the world > http://moblin-contest.org/redirect.php?banner_id=100&url=/ > _______________________________________________ > sleuthkit-developers mailing list > sle...@li... > https://lists.sourceforge.net/lists/listinfo/sleuthkit-developers > |
From: Brian C. <ca...@sl...> - 2008-10-27 17:46:24
|
Any win32 developers know why TSK is getting a sharing error (0x20) with this statement: raw_info->fd = CreateFile(image, GENERIC_READ, FILE_SHARE_READ | FILE_SHARE_WRITE, 0, OPEN_EXISTING, 0, 0); when trying to open "\\.\PhysicalDrive0" ? |
From: Brian C. <ca...@sl...> - 2008-09-29 03:31:38
|
FYI: The subversion repositories for TSK and Autopsy have been created. See: http://wiki.sleuthkit.org/index.php?title=TSK_Developer%27s_Guide http://wiki.sleuthkit.org/index.php?title=Autopsy_Developer%27s_Guide |
From: Michael C. <scu...@gm...> - 2008-09-28 23:03:04
|
Brian, We just run the script prior to release. It just runs sed over all the files and updates the $Version$ string with the release version and the date the script was run on. We then do a make dist* and upload the tar ball. Michael. On Mon, Sep 29, 2008 at 12:53 AM, Brian Carrier <ca...@sl...> wrote: > > On Sep 27, 2008, at 7:15 PM, Michael Cohen wrote: > >> Hi Brian, >> The whole keyword expansion thing imho is just a hack its not really >> needed since any decent VC system can tell you the latest date a file >> was changed. The only thing we have in the top of our files is a >> version string which contains a date a release was made (not when the >> file was changed). This then makes it easier to see which actual >> release a file came from when not under version control. >> >> We just use a quick bash script to sed the version string in prior to >> release. > > Do you do that as part of 'make dist' in auto* or do you do it as a separate > process? > >> I vote to remove the whole keyword expansion thing. > > Done. I just removed them all. > > brian > > |