sleuthkit-users Mailing List for The Sleuth Kit (Page 160)
Brought to you by:
carrier
You can subscribe to this list here.
| 2002 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
(6) |
Aug
|
Sep
(11) |
Oct
(5) |
Nov
(4) |
Dec
|
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2003 |
Jan
(1) |
Feb
(20) |
Mar
(60) |
Apr
(40) |
May
(24) |
Jun
(28) |
Jul
(18) |
Aug
(27) |
Sep
(6) |
Oct
(14) |
Nov
(15) |
Dec
(22) |
| 2004 |
Jan
(34) |
Feb
(13) |
Mar
(28) |
Apr
(23) |
May
(27) |
Jun
(26) |
Jul
(37) |
Aug
(19) |
Sep
(20) |
Oct
(39) |
Nov
(17) |
Dec
(9) |
| 2005 |
Jan
(45) |
Feb
(43) |
Mar
(66) |
Apr
(36) |
May
(19) |
Jun
(64) |
Jul
(10) |
Aug
(11) |
Sep
(35) |
Oct
(6) |
Nov
(4) |
Dec
(13) |
| 2006 |
Jan
(52) |
Feb
(34) |
Mar
(39) |
Apr
(39) |
May
(37) |
Jun
(15) |
Jul
(13) |
Aug
(48) |
Sep
(9) |
Oct
(10) |
Nov
(47) |
Dec
(13) |
| 2007 |
Jan
(25) |
Feb
(4) |
Mar
(2) |
Apr
(29) |
May
(11) |
Jun
(19) |
Jul
(13) |
Aug
(15) |
Sep
(30) |
Oct
(12) |
Nov
(10) |
Dec
(13) |
| 2008 |
Jan
(2) |
Feb
(54) |
Mar
(58) |
Apr
(43) |
May
(10) |
Jun
(27) |
Jul
(25) |
Aug
(27) |
Sep
(48) |
Oct
(69) |
Nov
(55) |
Dec
(43) |
| 2009 |
Jan
(26) |
Feb
(36) |
Mar
(28) |
Apr
(27) |
May
(55) |
Jun
(9) |
Jul
(19) |
Aug
(16) |
Sep
(15) |
Oct
(17) |
Nov
(70) |
Dec
(21) |
| 2010 |
Jan
(56) |
Feb
(59) |
Mar
(53) |
Apr
(32) |
May
(25) |
Jun
(31) |
Jul
(36) |
Aug
(11) |
Sep
(37) |
Oct
(19) |
Nov
(23) |
Dec
(6) |
| 2011 |
Jan
(21) |
Feb
(20) |
Mar
(30) |
Apr
(30) |
May
(74) |
Jun
(50) |
Jul
(34) |
Aug
(34) |
Sep
(12) |
Oct
(33) |
Nov
(10) |
Dec
(8) |
| 2012 |
Jan
(23) |
Feb
(57) |
Mar
(26) |
Apr
(14) |
May
(27) |
Jun
(27) |
Jul
(60) |
Aug
(88) |
Sep
(13) |
Oct
(36) |
Nov
(97) |
Dec
(85) |
| 2013 |
Jan
(60) |
Feb
(24) |
Mar
(43) |
Apr
(32) |
May
(22) |
Jun
(38) |
Jul
(51) |
Aug
(50) |
Sep
(76) |
Oct
(65) |
Nov
(25) |
Dec
(30) |
| 2014 |
Jan
(19) |
Feb
(41) |
Mar
(43) |
Apr
(28) |
May
(61) |
Jun
(12) |
Jul
(10) |
Aug
(37) |
Sep
(76) |
Oct
(31) |
Nov
(41) |
Dec
(12) |
| 2015 |
Jan
(33) |
Feb
(28) |
Mar
(53) |
Apr
(22) |
May
(29) |
Jun
(20) |
Jul
(15) |
Aug
(17) |
Sep
(52) |
Oct
(3) |
Nov
(18) |
Dec
(21) |
| 2016 |
Jan
(20) |
Feb
(8) |
Mar
(21) |
Apr
(7) |
May
(13) |
Jun
(35) |
Jul
(34) |
Aug
(11) |
Sep
(14) |
Oct
(22) |
Nov
(31) |
Dec
(23) |
| 2017 |
Jan
(20) |
Feb
(7) |
Mar
(5) |
Apr
(6) |
May
(6) |
Jun
(22) |
Jul
(11) |
Aug
(16) |
Sep
(8) |
Oct
(1) |
Nov
(1) |
Dec
(1) |
| 2018 |
Jan
|
Feb
|
Mar
(16) |
Apr
(2) |
May
(6) |
Jun
(5) |
Jul
|
Aug
(2) |
Sep
(4) |
Oct
|
Nov
(16) |
Dec
(13) |
| 2019 |
Jan
|
Feb
(1) |
Mar
(25) |
Apr
(9) |
May
(2) |
Jun
(1) |
Jul
(1) |
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
| 2020 |
Jan
(2) |
Feb
|
Mar
(1) |
Apr
|
May
(1) |
Jun
(3) |
Jul
(2) |
Aug
|
Sep
|
Oct
(5) |
Nov
|
Dec
|
| 2021 |
Jan
|
Feb
|
Mar
(1) |
Apr
|
May
|
Jun
(4) |
Jul
(1) |
Aug
|
Sep
(1) |
Oct
|
Nov
(1) |
Dec
|
| 2022 |
Jan
|
Feb
(2) |
Mar
|
Apr
|
May
(2) |
Jun
|
Jul
(3) |
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
| 2023 |
Jan
(2) |
Feb
|
Mar
(1) |
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
(1) |
Nov
|
Dec
|
| 2024 |
Jan
|
Feb
(3) |
Mar
|
Apr
(1) |
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
| 2025 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
(1) |
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
|
From: Simson G. <si...@ac...> - 2006-12-17 14:54:29
|
Hi. Cygwin is sometimes a problem. Here, in particular, the problem is that valloc() is not part of cygwin, but it is part of most modern Unix distributions. You can simply change "valloc" to "malloc" in line 542 of afflib_pages.cpp to fix the problem. The new release of AFFLIB also fixes this problem. You can download that from afflib.org. -Simson -Simson On Dec 17, 2006, at 4:17 AM, DePriest, Jason R. wrote: > On 12/17/06, DePriest, Jason R. wrote: >> I have been successfully running 2.06 on cygwin. >> >> I downloaded the source code for 2.07 and it will not compile. >> > > Source code compiles just fine on a Debian GNU/Linux system. Just > breaks on cygwin. > > Any other cygwin users having the same problem? > > -Jason > > ---------------------------------------------------------------------- > --- > Take Surveys. Earn Cash. Influence the Future of IT > Join SourceForge.net's Techsay panel and you'll get the chance to > share your > opinions on IT & business topics through brief surveys - and earn cash > http://www.techsay.com/default.php? > page=join.php&p=sourceforge&CID=DEVDEV > _______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org > |
|
From: DePriest, J. R. <jrd...@gm...> - 2006-12-17 09:17:23
|
On 12/17/06, DePriest, Jason R. wrote: > I have been successfully running 2.06 on cygwin. > > I downloaded the source code for 2.07 and it will not compile. > Source code compiles just fine on a Debian GNU/Linux system. Just breaks on cygwin. Any other cygwin users having the same problem? -Jason |
|
From: DePriest, J. R. <jrd...@gm...> - 2006-12-17 08:08:33
|
I have been successfully running 2.06 on cygwin.
I downloaded the source code for 2.07 and it will not compile.
The errors I receive are:
make[1]: Entering directory `/incoming/sleuthkit-2.07/src/afflib/lib'
if g++ -DHAVE_CONFIG_H -I. -I. -I.. -I../lzma443/C
-I../lzma443/C/7zip/Compress/LZMA_Alone -g -O2
-MT aff_db.o -MD -MP -MF ".deps/aff_db.Tpo" -c -o aff_db.o aff_db.cpp;
\
then mv -f ".deps/aff_db.Tpo" ".deps/aff_db.Po"; else rm -f
".deps/aff_db.Tpo"; ex it 1; fi
if g++ -DHAVE_CONFIG_H -I. -I. -I.. -I../lzma443/C
-I../lzma443/C/7zip/Compress/LZMA_Alone -g -O2
-MT aff_toc.o -MD -MP -MF ".deps/aff_toc.Tpo" -c -o aff_toc.o
aff_toc.cpp; \
then mv -f ".deps/aff_toc.Tpo" ".deps/aff_toc.Po"; else rm -f
".deps/aff_toc.Tpo"; exit 1; fi
if g++ -DHAVE_CONFIG_H -I. -I. -I.. -I../lzma443/C
-I../lzma443/C/7zip/Compress/LZMA_Alone -g -O2
-MT afflib.o -MD -MP -MF ".deps/afflib.Tpo" -c -o afflib.o afflib.cpp;
\
then mv -f ".deps/afflib.Tpo" ".deps/afflib.Po"; else rm -f
".deps/afflib.Tpo"; ex it 1; fi
if g++ -DHAVE_CONFIG_H -I. -I. -I.. -I../lzma443/C
-I../lzma443/C/7zip/Compress/LZMA_Alone -g -O2
-MT afflib_os.o -MD -MP -MF ".deps/afflib_os.Tpo" -c -o afflib_os.o
afflib_os. cpp; \
then mv -f ".deps/afflib_os.Tpo" ".deps/afflib_os.Po"; else rm
-f ".deps/afflib_os .Tpo"; exit 1; fi
if g++ -DHAVE_CONFIG_H -I. -I. -I.. -I../lzma443/C
-I../lzma443/C/7zip/Compress/LZMA_Alone -g -O2
-MT afflib_pages.o -MD -MP -MF ".deps/afflib_pages.Tpo" -c -o
afflib_pages.o a fflib_pages.cpp; \
then mv -f ".deps/afflib_pages.Tpo" ".deps/afflib_pages.Po";
else rm -f ".deps/aff lib_pages.Tpo"; exit 1; fi
afflib_pages.cpp: In function `aff_pagebuf* af_cache_alloc(AFFILE*, int64)':
afflib_pages.cpp:542: error: `valloc' undeclared (first use this function)
afflib_pages.cpp:542: error: (Each undeclared identifier is reported
only once for each fu nction it appears in.)
make[1]: *** [afflib_pages.o] Error 1
make[1]: Leaving directory `/incoming/sleuthkit-2.07/src/afflib/lib'
Error: Missing lib/libafflib.a file
make: *** [no-perl] Error 1
The file it says it not there really is not there.
What else can I provide that would be helpful?
I have tried this on two different systems, both running Windows 2003
Enterprise Server and cygwin 1.5.22(0.156/4/2)
Thanks!
-Jason
|
|
From: Brian C. <ca...@sl...> - 2006-12-15 19:55:38
|
Version 2.07 of TSK is now available in source and Win32 executable form: www.sleuthkit.org/sleuthkit/ There are a lot of updates and bug fixes. The summarized list is below. The executive summary is that there are new flags for ils to find orphan files and new flags for dls to specify allocation status. There were a lot of internal updates as well. There were a few NTFS bug fixes as well and a sorter fix for Cygwin. brian MD5 (sleuthkit-2.07.tar.gz) = 8165ef1c657e7ebca7a61542f784a04b MD5 (sleuthkit-win32-2.07.zip) = fc723f5f22ac750b89b96fbefa5f9b75 Updates: - Added '-p' flag to ils to find orphan files - added '-a' and '-A' flags to dls to specify allocation status - Detect and prevent infinite loops in corrupt directories and FAT files. - Updated AFFLIB, libewf, and file - improved FAT dentry detection (check size) - new internal fs_read_file() - Windows visual studio files included with source code - cleaned up error reporting code - added caching to FAT code. - Added a NULL check to fs_inode_free (Michael Cohen) - Improved ifind_path code so that allocated names are given priority (Dave Collett) Bug Fixes: - NTFS compression bug with corrupt data - sanity check to dcat_lib in case the requested number of blocks was too big. - fs_data lookup bug fixes by Dave Collett. - sorter does not clear path so it can run under Cygwin - Memory leak fixes in FAT and NTFS. |
|
From: DePriest, J. R. <jrd...@gm...> - 2006-12-08 14:51:35
|
T24gMTIvNy8wNiwgzfUg7M8gIHdyb3RlOgo+IEhpLEkgd2FudCBjcmVhdCBhIGRpc2sgaW1hZ2Us IGFuZCB0aGlzIGRpc2sgaXMgVVNCIGRpc2suIEkgaW5wdXQgZGQKPiBjb21tYW5kImRkIGlmPScv Y3lnZHJpdmUvaycgb2Y9a2RyaXZlMC5pbWciLCBidXQgaXQgc2hvd3MgbGlrZSB0aGlzOgo+ICAg IGRkOnJlYWRpbmcgJy9jeWdkcml2ZS9rJzogSXMgYSBkaXJlY3RvcnkKPiAwKzAgcmVjb3JkcyBp bgo+IDArMCByZWNvcmRzIG91dAo+IDAgYnl0ZXMgPDAgQj4gY29waWVkLCAwLjAwMSBzLCAwIEIv cwo+IEkgd2FudCB0byBrbm93IGhvdyB0byBzb2x2ZSB0aGlzIHByb2JsZW0uCj4gVGhhbmsgeW91 IQo+CgpUaGlzIGlzIHJlYWxseSBtb3JlIG9mIGEgQ3lnd2luIGlzc3VlIHRoYW4gYSBTbGV1dGhr aXQgaXNzdWUuCgpCdXQgc2luY2UgSSB1c2UgQ3lnd2luICsgU2xldXRoa2l0IGFsbCB0aGUgdGlt ZSwgSSBrbm93IGhvdyB0byBnZXQgaXQKd29ya2luZyAoaG9wZWZ1bGx5KS4KCkluIHRoZSBDeWd3 aW4gVXNlcnMgR3VpZGUsIHRoZXJlIGlzIGEgc2VjdGlvbiBvbiBob3cgaXQgZG9lcyAic3BlY2lh bApmaWxlbmFtZXMiLgoKUmVhZCBpdCBoZXJlOiBodHRwOi8vY3lnd2luLmNvbS9jeWd3aW4tdWct bmV0L3VzaW5nLXNwZWNpYWxuYW1lcy5odG1sCgpUaGUgcGFydCB5b3UgYXJlIGludGVyZXN0ZWQg aW4gaXMgd2hlcmUgaXQgdXNlcyAvZGV2L3NkWCB0byBtYXAgdG8gdGhlCnBoeXNpY2FsIGhhcmQg ZGlzayBkcml2ZXMuICBUaGUgJ2N5Z2RyaXZlJyBub3RhdGlvbiBtYXBzIHRvIHRoZQpsb2dpY2Fs IGRyaXZlcyBvbmx5LgoKSSBob3BlIHRoaXMgaGVscHMhCgotSmFzb24K |
|
From: <por...@ho...> - 2006-12-08 01:18:05
|
Hi,I want creat a disk image, and this disk is USB disk. I input dd command"dd if='/cygdrive/k' of=kdrive0.img", but it shows like this: dd:reading '/cygdrive/k': Is a directory 0+0 records in 0+0 records out 0 bytes <0 B> copied, 0.001 s, 0 B/s I want to know how to solve this problem. Thank you! _________________________________________________________________ 与联机的朋友进行交流,请使用 MSN Messenger: http://messenger.msn.com/cn |
|
From: Brian C. <ca...@sl...> - 2006-12-06 22:41:14
|
The README in the windows zip file is from the Unix version. The =20 README-win32.txt is the Windows-specific one. There is no INSTALL file in the Windows version since it simply =20 contains the executables. There is nothing to install. brian On Dec 6, 2006, at 2:51 AM, Lars H=E5kansson wrote: > Where can I find the INSTALL document referred to in README in =20 > sleuthkit-win32-2.06r2. > > > > ----------------------------------------------------------------------=20= > --- > Take Surveys. Earn Cash. Influence the Future of IT > Join SourceForge.net's Techsay panel and you'll get the chance to =20 > share your > opinions on IT & business topics through brief surveys - and earn cash > http://www.techsay.com/default.php?=20 > page=3Djoin.php&p=3Dsourceforge&CID=3DDEVDEV____________________________= ____=20 > _______________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org |
|
From: <lh...@li...> - 2006-12-06 07:51:42
|
Where can I find the INSTALL document referred to in README in = sleuthkit-win32-2.06r2. =20 |
|
From: DePriest, J. R. <jrd...@gm...> - 2006-12-02 00:34:29
|
> DePriest, Jason R. wrote: > > > Active File Recovery 7.1 build 333 (commercial program) found an NTFS > > partition on the drive. > > > > It starts at sector 1120 and is 35544920 sectors long. It has the > > default NTFS cluster size of 4096. I'm done with this, I think. It just gets weirder and weirder, though. Active File Recovery let me GUI my way into creating a forensic image of just the partition that it found that looked like a legitimate operating system. Sleuthkit was able to work with the resulting image just fine. Which leads me to unanswered questions, which I will probably never get answers for. Why was the partition started on sector 1120 instead of 63? What was the original server configuration and how did the drive I have relate to "the other two drives" that were mentioned as being discarded? If this was a RAID configuration, what was it so that I could get a valid partition out of just a single disk? My conclusion for the lawyers after looking at this drive and an IDE drive they also sent is: not enough information to provide any meaningful conclusion. All my questions, all my work, and all the inconclusive results have been documented and sent to my manager for approval. Thanks for everyone's suggestions. -Jason |
|
From: Brian C. <ca...@sl...> - 2006-11-30 14:14:52
|
On Nov 30, 2006, at 2:06 AM, vattini giacomo wrote: > > > Tom Ricardo <tom...@ya...> ha scritto: when I try to > install sleuthkit on my MAC OS X i get that darwin does not > understand the command "make". What should I try? > DO you got the source installed i mean the gcc for SO you will find > it with the dvd installation > to me it worked > A question for the list how can i run the program on a usb key or > in another way is that possible? You can simply copy the executables to a USB key. > with a live cd running sleuthkit can i view the files without > doing an image? knowing the cluster position without destroying > that?And do you know if under MACOSX is there a livecd with such a > program? Yes, many of the forensics / security Linux CDs include TSK. There is a basic list on sleuthkit.org/links.php I haven't used any with Macs though. brian |
|
From: vattini g. <ha...@ya...> - 2006-11-30 07:06:36
|
Tom Ricardo <tom...@ya...> ha scritto: when I try to install sleuthkit on my MAC OS X i get that darwin does not understand the command "make". What should I try? DO you got the source installed i mean the gcc for SO you will find it with the dvd installation to me it worked A question for the list how can i run the program on a usb key or in another way is that possible?with a live cd running sleuthkit can i view the files without doing an image?knowing the cluster position without destroying that?And do you know if under MACOSX is there a livecd with such a program? __________________________________________________ Do You Yahoo!? Poco spazio e tanto spam? Yahoo! Mail ti protegge dallo spam e ti da tanto spazio gratuito per i tuoi file e i messaggi http://mail.yahoo.it |
|
From: DePriest, J. R. <jrd...@gm...> - 2006-11-29 00:10:58
|
On 11/28/06, Frank_Kenisky wrote: > > > Thanks > > I tried several things and still couldn't see any data. Do you mean that if you do a hexedit of the disk, all you see are 0x00s? Or just that there is no data that you have an application to interpret? Can you take another mini-dv that you know works properly and see what sort of luck you have with that? Maybe dd both of them and compare the hex to look for similarities that might lead to discovering information about the file system. Just reading a few articles from a google search makes me wonder if you need to use tools designed to work with streaming data. Mini-dv is a tape-based format, so tools for DVDs and CDs (and hard disk drives) may not work. What would someone use to forensically examine a DAT or DLT? |
|
From: Simson L. G. <si...@ac...> - 2006-11-28 15:14:52
|
You need to install the developer tools disk or run prebuilt binaries. ----- Original Message -----=20 From: Tom Ricardo=20 To: sle...@li...=20 Sent: Tuesday, November 28, 2006 10:11 AM Subject: [sleuthkit-users] Mac OSX/ Darwin installation when I try to install sleuthkit on my MAC OS X i get that darwin does = not understand the command "make". What should I try? -------------------------------------------------------------------------= ----- Cheap Talk? Check out Yahoo! Messenger's low PC-to-Phone call rates. -------------------------------------------------------------------------= ----- = -------------------------------------------------------------------------= Take Surveys. Earn Cash. Influence the Future of IT Join SourceForge.net's Techsay panel and you'll get the chance to = share your opinions on IT & business topics through brief surveys - and earn cash = http://www.techsay.com/default.php?page=3Djoin.php&p=3Dsourceforge&CID=3D= DEVDEV -------------------------------------------------------------------------= ----- _______________________________________________ sleuthkit-users mailing list https://lists.sourceforge.net/lists/listinfo/sleuthkit-users http://www.sleuthkit.org |
|
From: Simson L. G. <si...@ac...> - 2006-11-28 15:14:09
|
if you "dd" the disk, do you get any data at all?
----- Original Message -----=20
From: Fra...@ps...=20
To: Brian Carrier=20
Cc: sle...@li... ; =
sle...@li... ; DePriest, Jason R.=20
Sent: Tuesday, November 28, 2006 9:48 AM
Subject: Re: [sleuthkit-users] Examining a dvd disk made using a DV =
camera
Thanks=20
I tried several things and still couldn't see any data. I have a dvd =
burner on my laptop, downloaded isobuster and couldn't see anything on =
the disk. I tried using a disk I had previously burned and all the data =
showed up. I can see that something was written to the disk but I just =
can't get to it.=20
I've got image scan 2.1 from the fbi but the formats it looks for may =
not include the ones for burned dvds.=20
Thanks again=20
Frank Kenisky IV, CISSP, CISA, CISM
Information Technical Security Specialist
(210) 301-6433 - (210) 887-6985=20
Brian Carrier <ca...@sl...>=20
Sent by: sle...@li...=20
11/28/2006 08:21 AM=20
To Fra...@ps... =20
cc "DePriest, Jason R." <jrd...@gm...>, =
sle...@li..., =
sle...@li... =20
Subject Re: [sleuthkit-users] Examining a dvd disk made =
using a DV camera=20
=20
=20
I personally don't know much about the DVD format, but I doubt TSK =20
will help. I've used ISOBuster for CDs before and the website says =20
it works for DVDs as well.
brian
On Nov 27, 2006, at 10:29 AM, Fra...@ps... wrote:
>
> Not sure if this can be done with sleuth-kit, but I've been asked =20
> to see if I can recover files from a mini dvd made using a DV =20
> camera. Apparently it was finalized but now gives the user a disk =20
> failure.
>
> When I look at the disk using winxp in explorer it appears empty.
>
> Any suggestions on the disk type (ntfs, fat, etc) and where I might =
> start.
>
> Thanks
>
> Frank Kenisky IV, CISSP, CISA, CISM
> Information Technical Security Specialist
> (210) 301-6433 - (210) 887-6985
> =
----------------------------------------------------------------------=20
> ---
> Take Surveys. Earn Cash. Influence the Future of IT
> Join SourceForge.net's Techsay panel and you'll get the chance to =20
> share your
> opinions on IT & business topics through brief surveys - and earn =
cash
> http://www.techsay.com/default.php?=20
> =
page=3Djoin.php&p=3Dsourceforge&CID=3DDEVDEV_____________________________=
___=20
> _______________
> sleuthkit-users mailing list
> https://lists.sourceforge.net/lists/listinfo/sleuthkit-users
> http://www.sleuthkit.org
=
-------------------------------------------------------------------------=
Take Surveys. Earn Cash. Influence the Future of IT
Join SourceForge.net's Techsay panel and you'll get the chance to =
share your
opinions on IT & business topics through brief surveys - and earn cash
=
http://www.techsay.com/default.php?page=3Djoin.php&p=3Dsourceforge&CID=3D=
DEVDEV
_______________________________________________
sleuthkit-users mailing list
https://lists.sourceforge.net/lists/listinfo/sleuthkit-users
http://www.sleuthkit.org
-------------------------------------------------------------------------=
-----
=
-------------------------------------------------------------------------=
Take Surveys. Earn Cash. Influence the Future of IT
Join SourceForge.net's Techsay panel and you'll get the chance to =
share your
opinions on IT & business topics through brief surveys - and earn cash
=
http://www.techsay.com/default.php?page=3Djoin.php&p=3Dsourceforge&CID=3D=
DEVDEV
-------------------------------------------------------------------------=
-----
_______________________________________________
sleuthkit-users mailing list
https://lists.sourceforge.net/lists/listinfo/sleuthkit-users
http://www.sleuthkit.org
|
|
From: Tom R. <tom...@ya...> - 2006-11-28 15:11:55
|
when I try to install sleuthkit on my MAC OS X i get that darwin does not understand the command "make". What should I try? --------------------------------- Cheap Talk? Check out Yahoo! Messenger's low PC-to-Phone call rates. |
|
From: <Fra...@ps...> - 2006-11-28 14:48:45
|
Thanks I tried several things and still couldn't see any data. I have a dvd burner on my laptop, downloaded isobuster and couldn't see anything on the disk. I tried using a disk I had previously burned and all the data showed up. I can see that something was written to the disk but I just can't get to it. I've got image scan 2.1 from the fbi but the formats it looks for may not include the ones for burned dvds. Thanks again Frank Kenisky IV, CISSP, CISA, CISM Information Technical Security Specialist (210) 301-6433 - (210) 887-6985 Brian Carrier <ca...@sl...> Sent by: sle...@li... 11/28/2006 08:21 AM To Fra...@ps... cc "DePriest, Jason R." <jrd...@gm...>, sle...@li..., sle...@li... Subject Re: [sleuthkit-users] Examining a dvd disk made using a DV camera I personally don't know much about the DVD format, but I doubt TSK will help. I've used ISOBuster for CDs before and the website says it works for DVDs as well. brian On Nov 27, 2006, at 10:29 AM, Fra...@ps... wrote: > > Not sure if this can be done with sleuth-kit, but I've been asked > to see if I can recover files from a mini dvd made using a DV > camera. Apparently it was finalized but now gives the user a disk > failure. > > When I look at the disk using winxp in explorer it appears empty. > > Any suggestions on the disk type (ntfs, fat, etc) and where I might > start. > > Thanks > > Frank Kenisky IV, CISSP, CISA, CISM > Information Technical Security Specialist > (210) 301-6433 - (210) 887-6985 > ---------------------------------------------------------------------- > --- > Take Surveys. Earn Cash. Influence the Future of IT > Join SourceForge.net's Techsay panel and you'll get the chance to > share your > opinions on IT & business topics through brief surveys - and earn cash > http://www.techsay.com/default.php? > page=join.php&p=sourceforge&CID=DEVDEV________________________________ > _______________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org ------------------------------------------------------------------------- Take Surveys. Earn Cash. Influence the Future of IT Join SourceForge.net's Techsay panel and you'll get the chance to share your opinions on IT & business topics through brief surveys - and earn cash http://www.techsay.com/default.php?page=join.php&p=sourceforge&CID=DEVDEV _______________________________________________ sleuthkit-users mailing list https://lists.sourceforge.net/lists/listinfo/sleuthkit-users http://www.sleuthkit.org |
|
From: Brian C. <ca...@sl...> - 2006-11-28 14:21:36
|
I personally don't know much about the DVD format, but I doubt TSK will help. I've used ISOBuster for CDs before and the website says it works for DVDs as well. brian On Nov 27, 2006, at 10:29 AM, Fra...@ps... wrote: > > Not sure if this can be done with sleuth-kit, but I've been asked > to see if I can recover files from a mini dvd made using a DV > camera. Apparently it was finalized but now gives the user a disk > failure. > > When I look at the disk using winxp in explorer it appears empty. > > Any suggestions on the disk type (ntfs, fat, etc) and where I might > start. > > Thanks > > Frank Kenisky IV, CISSP, CISA, CISM > Information Technical Security Specialist > (210) 301-6433 - (210) 887-6985 > ---------------------------------------------------------------------- > --- > Take Surveys. Earn Cash. Influence the Future of IT > Join SourceForge.net's Techsay panel and you'll get the chance to > share your > opinions on IT & business topics through brief surveys - and earn cash > http://www.techsay.com/default.php? > page=join.php&p=sourceforge&CID=DEVDEV________________________________ > _______________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org |
|
From: <Fra...@ps...> - 2006-11-27 15:29:39
|
Not sure if this can be done with sleuth-kit, but I've been asked to see if I can recover files from a mini dvd made using a DV camera. Apparently it was finalized but now gives the user a disk failure. When I look at the disk using winxp in explorer it appears empty. Any suggestions on the disk type (ntfs, fat, etc) and where I might start. Thanks Frank Kenisky IV, CISSP, CISA, CISM Information Technical Security Specialist (210) 301-6433 - (210) 887-6985 |
|
From: Brian C. <ca...@sl...> - 2006-11-21 17:33:26
|
DePriest, Jason R. wrote: > Active File Recovery 7.1 build 333 (commercial program) found an NTFS > partition on the drive. > > It starts at sector 1120 and is 35544920 sectors long. It has the > default NTFS cluster size of 4096. > > It seems to have an full Windows file system on it with enough > directories to actually boot and run. > > According to AFR, there are exactly 0 (zero) deleted files on it. > > I am disturbed by that result. I can't seem to get the partition > recognized by any of the autopsy tools to verify that number. Currently, Autopsy does not allow you to specify the location of arbitrary partitions (it requires 'mmls' to find them from a partition table). Since you know the offset, you can run 'fls -o 1120 IMG.img' on the image and see what it comes back with. Is this from the RAID array or the other stand-alone drive? If it is one of the RAID drives, then I assume you'll get a bunch of errors since data will be missing. brian |
|
From: Gary F. <ga...@in...> - 2006-11-21 16:28:36
|
Brian Carrier wrote: > If you know the address of the bad blocks, then you can use > 'ifind' to > find out if the block is allocated to an inode/MFT Entry. > You can then > use ils or istat to find out if the inode/MFT Entry is currently > allocated or not. OK. I'll give that a try. Please note my reply to Simson for additional background. I think the challenge may be automating the steps outlined above. |
|
From: Gary F. <ga...@in...> - 2006-11-21 16:21:12
|
> -----Original Message----- Simson Garfinkel wrote: > Sleuthkit can't do this out-of-the-box. Are you really > running Sleuth > Kit on the raw drive? No. We plan to run Sleuthkit on the image of the drive. However, the image has known hardware errors, where the error sectors have been replaced with zeros. The dclfdd output looks something like this: dcfldd:/dev/hde: Input/output error 6601392+31 records in 6601423+0 records out dcfldd:/dev/hde: Input/output error 18533840+32 records in 18533872+0 records out dcfldd:/dev/hde: Input/output error 18533840+33 records in 18533873+0 records out The original dclfdd command was something like this: dcfldd if=/dev/hde of=/evidence/Dell8100.img bs=512 \ hash=md5 conv=error,sync \ hashlog=/evidence/Dell8100.md5 \ errlog=/evidence/Dell8100.err_log There is sufficient information in the error log to determine which blocks (sectors) had read errors. > > However, the combination of aimage & sleuthkit and some fancy > software that I am working can do this pretty easily. What would you > use it for? Please tell us more about that fancy software. <g> Generally, I planned on simply having the imaging script identify the file data and/or metadata that had likely been lost. What we typically do in the case that the drive has errors is to copy the image file back onto a scratch drive, and then run chkdsk or its equivalent on the scratch drive, and then run our analysis on the resulting file system(s). We'd take the same steps if we were simply restoring a failing drive by copying it to a new drive (first make an image, then copy the image to the new drive, then run chkdsk). However, from what I recall, chkdsk doesn't print any information regarding which files or data might have been lost during the fix up pass. As a matter of completeness, we'd like to have that information, and we'd like to obtain that information as part of the drive imaging process, in an automated fashion. |
|
From: DePriest, J. R. <jrd...@gm...> - 2006-11-21 05:47:20
|
On 11/21/06, Brian Carrier wrote: > > No, I think you are out of luck. TSK requires at least a minimal amount > of basic information from a boot sector / super block and you may not > even have that in this case since you are missing two of the RAID > drives. You may consider looking into testdisk or gpart to see if they > can scavenge any file system traces from the image. > > brian > I have something magical to report. Active File Recovery 7.1 build 333 (commercial program) found an NTFS partition on the drive. It starts at sector 1120 and is 35544920 sectors long. It has the default NTFS cluster size of 4096. It seems to have an full Windows file system on it with enough directories to actually boot and run. According to AFR, there are exactly 0 (zero) deleted files on it. I am disturbed by that result. I can't seem to get the partition recognized by any of the autopsy tools to verify that number. -Jason -- |
|
From: Brian C. <ca...@sl...> - 2006-11-21 05:06:40
|
Simson Garfinkel wrote: > > On Nov 19, 2006, at 6:00 PM, DePriest, Jason R. wrote: > >> >> My question is this: how can such evidence be found when the file >> system is not mountable? If there is not a recognized file system to >> provide the references and pointers to files and file names, how can >> you know what was deleted and what was still a file? > > Depends on what the file system is. If it is FAT32, then the first > character of filenames will be changed when they are deleted. You might > recover directory entries even if the file system is not recoverable. Similarly with NTFS, but it will require you to look at the allocation status in the MFT entry flags. If you know the type of source code, you could do a UTF-16 search for ".cpp" (or similar) to get the file name entries. >> Is there anyway I can force any of the sleuthkit tools to see it as >> such and extract a real file list from it? No, I think you are out of luck. TSK requires at least a minimal amount of basic information from a boot sector / super block and you may not even have that in this case since you are missing two of the RAID drives. You may consider looking into testdisk or gpart to see if they can scavenge any file system traces from the image. brian |
|
From: Brian C. <ca...@sl...> - 2006-11-21 04:47:10
|
If you know the address of the bad blocks, then you can use 'ifind' to find out if the block is allocated to an inode/MFT Entry. You can then use ils or istat to find out if the inode/MFT Entry is currently allocated or not. brian Gary Funck wrote: > From time to time, we process a hard drive that has > a series of unrecoverable errors. We'd like a fairly > quick check that we can run while imaging the drive > that tells us if the bad blocks likely fall in > allocated space (inclusive of metadata), and if so, > which files (and/or metadata) might be affected. > It would also be nice to know if the bad blocks > are part of a deleted file as well, if applicable. > > Given that ntfs volumes are prevalent these > days, our primary interest is ntfs volumes, but > hopefully the same principles might apply to > FAT32, ext3 and other file system types as well. > > Can the sleuthkit tools perform this fucntion? > What would be the recommended sequnces of > commands that must be run to accomplish the task? |
|
From: Brian C. <ca...@sl...> - 2006-11-21 04:34:00
|
Brent Kidwell wrote:
> Thanks for the email.
>
> No, I'm not receiving any message about OpenSSL.
Did you make the change I mentioned and remove the PATH statement? I
was getting the same error message you did with Cygwin and that fixed it.
brian
>
> The only message returned is "incorrect file system type" reported back.
>
>
> On 11/17/06, *Brian Carrier* < ca...@sl...
> <mailto:ca...@sl...>> wrote:
>
> Are you getting a dialog box about not being able to find the OpenSSL
> dlls? When I just did a similar test, that is what I got and then got
> the same error. The problem is that sorter clears the PATH, but Cygwin
> needs to find the OpenSSL dlls for AFFLib. The quick fix is to edit
> bin/sorter and comment out line 21 (add a #):
>
> #$ENV{PATH} = '';
>
> brian
>
>
> Brent Kidwell wrote:
> > I have a dd image of an NTFS disk. I'm using the most recent
> build of
> > TSK under Cygwin on a XP machine.
> >
> > When I run sorter on the dd image and specify "-f ntfs", I get
> back an
> > error message "Incorrect file system type (-f ntfs)".
> >
> > Running fsstat on the same dd image returns recognition that this
> image
> > is indeed an NTFS file system.
> >
> > Any suggestions?
> >
> > For reference, here is the complete sorter command I am running:
> >
> > >> sorter -d c:\\output -h -s -n /usr/local/nsrl/NSRLFile.txt -m
> "E:/"
> > -f ntfs -i raw /usr/local/images/analysis.dd
> >
> > By the way, from within Autopsy the same error is generated.
> >
> > Many thanks.
> >
> > Brent
> >
> >
> >
> ------------------------------------------------------------------------
>
> >
> >
> -------------------------------------------------------------------------
> > Take Surveys. Earn Cash. Influence the Future of IT
> > Join SourceForge.net's Techsay panel and you'll get the chance to
> share your
> > opinions on IT & business topics through brief surveys - and earn
> cash
> >
> http://www.techsay.com/default.php?page=join.php&p=sourceforge&CID=DEVDEV
> <http://www.techsay.com/default.php?page=join.php&p=sourceforge&CID=DEVDEV>
> >
> >
> >
> ------------------------------------------------------------------------
> >
> > _______________________________________________
> > sleuthkit-users mailing list
> > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users
> > http://www.sleuthkit.org
>
>
>
> ------------------------------------------------------------------------
>
> -------------------------------------------------------------------------
> Take Surveys. Earn Cash. Influence the Future of IT
> Join SourceForge.net's Techsay panel and you'll get the chance to share your
> opinions on IT & business topics through brief surveys - and earn cash
> http://www.techsay.com/default.php?page=join.php&p=sourceforge&CID=DEVDEV
>
>
> ------------------------------------------------------------------------
>
> _______________________________________________
> sleuthkit-users mailing list
> https://lists.sourceforge.net/lists/listinfo/sleuthkit-users
> http://www.sleuthkit.org
|