sleuthkit-users Mailing List for The Sleuth Kit (Page 168)
Brought to you by:
carrier
You can subscribe to this list here.
| 2002 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
(6) |
Aug
|
Sep
(11) |
Oct
(5) |
Nov
(4) |
Dec
|
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2003 |
Jan
(1) |
Feb
(20) |
Mar
(60) |
Apr
(40) |
May
(24) |
Jun
(28) |
Jul
(18) |
Aug
(27) |
Sep
(6) |
Oct
(14) |
Nov
(15) |
Dec
(22) |
| 2004 |
Jan
(34) |
Feb
(13) |
Mar
(28) |
Apr
(23) |
May
(27) |
Jun
(26) |
Jul
(37) |
Aug
(19) |
Sep
(20) |
Oct
(39) |
Nov
(17) |
Dec
(9) |
| 2005 |
Jan
(45) |
Feb
(43) |
Mar
(66) |
Apr
(36) |
May
(19) |
Jun
(64) |
Jul
(10) |
Aug
(11) |
Sep
(35) |
Oct
(6) |
Nov
(4) |
Dec
(13) |
| 2006 |
Jan
(52) |
Feb
(34) |
Mar
(39) |
Apr
(39) |
May
(37) |
Jun
(15) |
Jul
(13) |
Aug
(48) |
Sep
(9) |
Oct
(10) |
Nov
(47) |
Dec
(13) |
| 2007 |
Jan
(25) |
Feb
(4) |
Mar
(2) |
Apr
(29) |
May
(11) |
Jun
(19) |
Jul
(13) |
Aug
(15) |
Sep
(30) |
Oct
(12) |
Nov
(10) |
Dec
(13) |
| 2008 |
Jan
(2) |
Feb
(54) |
Mar
(58) |
Apr
(43) |
May
(10) |
Jun
(27) |
Jul
(25) |
Aug
(27) |
Sep
(48) |
Oct
(69) |
Nov
(55) |
Dec
(43) |
| 2009 |
Jan
(26) |
Feb
(36) |
Mar
(28) |
Apr
(27) |
May
(55) |
Jun
(9) |
Jul
(19) |
Aug
(16) |
Sep
(15) |
Oct
(17) |
Nov
(70) |
Dec
(21) |
| 2010 |
Jan
(56) |
Feb
(59) |
Mar
(53) |
Apr
(32) |
May
(25) |
Jun
(31) |
Jul
(36) |
Aug
(11) |
Sep
(37) |
Oct
(19) |
Nov
(23) |
Dec
(6) |
| 2011 |
Jan
(21) |
Feb
(20) |
Mar
(30) |
Apr
(30) |
May
(74) |
Jun
(50) |
Jul
(34) |
Aug
(34) |
Sep
(12) |
Oct
(33) |
Nov
(10) |
Dec
(8) |
| 2012 |
Jan
(23) |
Feb
(57) |
Mar
(26) |
Apr
(14) |
May
(27) |
Jun
(27) |
Jul
(60) |
Aug
(88) |
Sep
(13) |
Oct
(36) |
Nov
(97) |
Dec
(85) |
| 2013 |
Jan
(60) |
Feb
(24) |
Mar
(43) |
Apr
(32) |
May
(22) |
Jun
(38) |
Jul
(51) |
Aug
(50) |
Sep
(76) |
Oct
(65) |
Nov
(25) |
Dec
(30) |
| 2014 |
Jan
(19) |
Feb
(41) |
Mar
(43) |
Apr
(28) |
May
(61) |
Jun
(12) |
Jul
(10) |
Aug
(37) |
Sep
(76) |
Oct
(31) |
Nov
(41) |
Dec
(12) |
| 2015 |
Jan
(33) |
Feb
(28) |
Mar
(53) |
Apr
(22) |
May
(29) |
Jun
(20) |
Jul
(15) |
Aug
(17) |
Sep
(52) |
Oct
(3) |
Nov
(18) |
Dec
(21) |
| 2016 |
Jan
(20) |
Feb
(8) |
Mar
(21) |
Apr
(7) |
May
(13) |
Jun
(35) |
Jul
(34) |
Aug
(11) |
Sep
(14) |
Oct
(22) |
Nov
(31) |
Dec
(23) |
| 2017 |
Jan
(20) |
Feb
(7) |
Mar
(5) |
Apr
(6) |
May
(6) |
Jun
(22) |
Jul
(11) |
Aug
(16) |
Sep
(8) |
Oct
(1) |
Nov
(1) |
Dec
(1) |
| 2018 |
Jan
|
Feb
|
Mar
(16) |
Apr
(2) |
May
(6) |
Jun
(5) |
Jul
|
Aug
(2) |
Sep
(4) |
Oct
|
Nov
(16) |
Dec
(13) |
| 2019 |
Jan
|
Feb
(1) |
Mar
(25) |
Apr
(9) |
May
(2) |
Jun
(1) |
Jul
(1) |
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
| 2020 |
Jan
(2) |
Feb
|
Mar
(1) |
Apr
|
May
(1) |
Jun
(3) |
Jul
(2) |
Aug
|
Sep
|
Oct
(5) |
Nov
|
Dec
|
| 2021 |
Jan
|
Feb
|
Mar
(1) |
Apr
|
May
|
Jun
(4) |
Jul
(1) |
Aug
|
Sep
(1) |
Oct
|
Nov
(1) |
Dec
|
| 2022 |
Jan
|
Feb
(2) |
Mar
|
Apr
|
May
(2) |
Jun
|
Jul
(3) |
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
| 2023 |
Jan
(2) |
Feb
|
Mar
(1) |
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
(1) |
Nov
|
Dec
|
| 2024 |
Jan
|
Feb
(3) |
Mar
|
Apr
(1) |
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
| 2025 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
(1) |
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
|
From: Stuart B. <e_t...@ya...> - 2006-04-21 08:33:02
|
Hi All Having recently had my linux exam box upgraded I decided to have a crack at a new setup so I took the plunge and had a go at installing Gentoo from their new installer CD. After a few weeks of general use I am very happy with it and it seems very stable. The first thing I wanted to ask is whether Gentoo is a good base for forensic work. As far as I can tell it does not auto mount anything without my say so, but are there any other areas of the distro I need to look at to make the environment forensically sound? Secondly, I have installed sleuthkit and autopsy via portage. I can run autopsy alright but cannot for the life of me find the directory that sleuthkit was installed to so that I can run stuff from the commandline. I have tried "find" and "locate" etc but I still can't find the folder containing all the commands. I am on Gentoo 2006.0 with kernel-genkernel-x86-2.6.15-gentoo-r5 if that helps. Any advice appreciated. Stu Bird ___________________________________________________________ Switch an email account to Yahoo! Mail, you could win FIFA World Cup tickets. http://uk.mail.yahoo.com |
|
From: Barry J. G. <bg...@im...> - 2006-04-20 14:10:57
|
On Thu, 2006-04-20 at 06:21 +0800, Jennifer Smith wrote: > farmer dude, thanks for the response - any suggestions on sites to > look for practice images (especially if they include a "results" list, > so I know if I actually find everything); also, is there a how-to > anywhere on creating images for practicing? There is a "practice" image included with the "Law Enforcement and Forensic Examiner's Introduction to Linux, a Beginner's Guide": ftp://ftp.hq.nasa.gov/pub/ig/ccd/linuxintro/ The guide includes a fairly indepth section on creating images using dd (indepth from a beginner's standpoint). The guide is due for an update, but it might help you out now. Barry -- /*************************************** Special Agent Barry J. Grundy NASA Office of Inspector General Computer Crimes Division Goddard Space Flight Center Code 190 Greenbelt Rd. Greenbelt, MD 20771 (301)286-3358 **************************************/ |
|
From: Patrick F. <fo...@ch...> - 2006-04-20 05:28:18
|
Jennifer Smith wrote: >Ok, I got the offset from mmls (thanks Barry, that was exactly what I needed to do!) and now sorter is running beautifully, with just one hangup. > >It appears that there are some file system compressed files in this image and when sorter gets to them it throws out an error that it can not access NTFS compressed files and then it aborts trying to access that particular file. These appear to be file system compressed files, not standard archive files, since it was able to sort and catalog .cab, .dat, and .zip files with no problem. > >According to some research on this end, it seems that NTFS uses something similar to DriveSpace3 for it's compression (please correct me if I'm wrong) - has anyone found/created any method to work through this error with sorter so that instead of aborting the file, it uncompresses it and sorts it as intended? > > > The unofficial NTFS driver for Linux handles compressed files. By loop-back mounting the image (read-only) you can get to the non-deleted compressed files. This shouldn't compromise the evidence as long as it is repeatable and yo can prove the image hasn't been modified (checksum you images). Unfortunately this method doesn't work for deleted files. I still find loop-back mounting the image file a great help in investigating since it's so much easier than just using TSK utilities. /Patrick |
|
From: DePriest, J. R. <jrd...@gm...> - 2006-04-19 22:57:00
|
Reading the NTFS entry in Wikipedia states that NTFS compresses uses the same compression algorithm as regular Zip files (LZ77): http://en.wikipedia.org/wiki/Ntfs That article had a link to the Microsoft website here: http://msdn.microsoft.com/library/default.asp?url=3D/library/en-us/fileio/f= s/file_compression_and_decompression.asp The site is pretty high level and doesn't really give much more detail than what apps or functions to call to perform an operation. It looks like someone would need to recreate the functionality of LzExpand.dll in an open source manner and I have no idea if any development is being done on this. I also don't know what the existing NTFS drivers and bolt-ons for Linux can already do natively. You could always note the files that cannot be decompressed, manually pull them out of the image and then use a Windows system to decompress them. Of course, that would compromise your evidence, but it is an idea. -Jason On 4/19/06, Jennifer Smith <> wrote: > Ok, I got the offset from mmls (thanks Barry, that was exactly what I nee= ded to do!) and now sorter is running beautifully, with just one hangup. > > It appears that there are some file system compressed files in this image= and when sorter gets to them it throws out an error that it can not access= NTFS compressed files and then it aborts trying to access that particular = file. These appear to be file system compressed files, not standard archive= files, since it was able to sort and catalog .cab, .dat, and .zip files wi= th no problem. > > According to some research on this end, it seems that NTFS uses something= similar to DriveSpace3 for it's compression (please correct me if I'm wron= g) - has anyone found/created any method to work through this error with so= rter so that instead of aborting the file, it uncompresses it and sorts it = as intended? > > farmer dude, thanks for the response - any suggestions on sites to look f= or practice images (especially if they include a "results" list, so I know = if I actually find everything); also, is there a how-to anywhere on creatin= g images for practicing? > > Thanks again for all the help, > gg > > |
|
From: Jennifer S. <g33...@li...> - 2006-04-19 22:22:50
|
Ok, I got the offset from mmls (thanks Barry, that was exactly what I neede= d to do!) and now sorter is running beautifully, with just one hangup. It appears that there are some file system compressed files in this image a= nd when sorter gets to them it throws out an error that it can not access N= TFS compressed files and then it aborts trying to access that particular fi= le. These appear to be file system compressed files, not standard archive f= iles, since it was able to sort and catalog .cab, .dat, and .zip files with= no problem. According to some research on this end, it seems that NTFS uses something s= imilar to DriveSpace3 for it's compression (please correct me if I'm wrong)= - has anyone found/created any method to work through this error with sort= er so that instead of aborting the file, it uncompresses it and sorts it as= intended? farmer dude, thanks for the response - any suggestions on sites to look for= practice images (especially if they include a "results" list, so I know if= I actually find everything); also, is there a how-to anywhere on creating = images for practicing? Thanks again for all the help, gg --=20 _______________________________________________ Check out the latest SMS services @ http://www.linuxmail.org This allows you to send and receive SMS through your mailbox. Powered by Outblaze |
|
From: farmer d. <far...@ya...> - 2006-04-19 17:40:30
|
--- Jennifer Smith <g33...@li...> wrote: > Thanks for the help with the path. I am now able to > run sorter, but I am getting an error that I don't > understand. I am running the following command > (from the /sleuthkit-2.03/ directory): > > perl ./bin/sorter -d [path where i want the > information saved]/sorted -f ntfs [path where the > image is]/file.dd > You can run './sorter' if you're in the '/usr/local/sleuthkit-2.03/bin' directory. OR symlink it to '/usr/local/bin' via; cd /usr/local/bin ln -s /usr/local/sleuthkit-2.03/bin/sorter sorter Now just run 'sorter XXX' as it's in your $PATH statement. > but I am getting the error "Incorrect file system > type (-f ntfs) > Bad FS type - another FS type or specify an offset to where the NTFS file system begins within the file. > > I determined that it was ntfs from the results I got > from Autopsy, but just in case, I also tried other > types in the command, all to no avail. Am I missing > something? > sfdisk -l -uS XXX Replace 'XXX' with your filename. Does this spit back a partition table to you? If so, post here or just calculate the offset to the 'mount' command where that NTFS file system begins with the file. > The .dd file that I am using is from the book _Real > Digital Forensics_ (I needed one to practice on), > and it worked (from what I can tell) in Autopsy. > Not familiar with the image file. Funny name, though. "REAL Digital Forensics." I wonder if it would sell using "FAKE Digital Forensics". lol ;) Too funny! If you're looking for an image file to poke and practice with you can grab them all over the net or I'll make one for ya. regards, farmerdude http://www.forensicbootcd.com/ --- Jennifer Smith <g33...@li...> wrote: > Thanks for the help with the path. I am now able to > run sorter, but I am getting an error that I don't > understand. I am running the following command > (from the /sleuthkit-2.03/ directory): > > perl ./bin/sorter -d [path where i want the > information saved]/sorted -f ntfs [path where the > image is]/file.dd > > but I am getting the error "Incorrect file system > type (-f ntfs) > > If I try running it without the -f flag at all, it > says "Missing file system type (and autodetect is > not working)" > > I determined that it was ntfs from the results I got > from Autopsy, but just in case, I also tried other > types in the command, all to no avail. Am I missing > something? > > The .dd file that I am using is from the book _Real > Digital Forensics_ (I needed one to practice on), > and it worked (from what I can tell) in Autopsy. > > I am pretty new to the Linux world of forensics > tools, so I really appreciate the guidance. Thanks > again for the help. > > And Brian, I have _File System Forensics_, too, I'm > just not quite to that level yet! Although I have > used it for reference :) > > Thanks again, > gg > > -- > _______________________________________________ > Check out the latest SMS services @ > http://www.linuxmail.org > This allows you to send and receive SMS through your > mailbox. > > Powered by Outblaze > > > ------------------------------------------------------- > Using Tomcat but need to do more? Need to support > web services, security? > Get stuff done quickly with pre-integrated > technology to make your job easier > Download IBM WebSphere Application Server v.1.0.1 > based on Apache Geronimo > http://sel.as-us.falkag.net/sel?cmd=lnk&kid0709&bid&3057&dat1642 > _______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org > __________________________________________________ Do You Yahoo!? Tired of spam? Yahoo! Mail has the best spam protection around http://mail.yahoo.com |
|
From: Barry J. G. <bg...@im...> - 2006-04-19 15:43:34
|
On Wed, 2006-04-19 at 21:41 +0800, Jennifer Smith wrote: > but I am getting the error "Incorrect file system type (-f ntfs) Hi Jennifer, I'm not familiar with the dd image from the book you are talking about. If it is a disk image, then you need to pass an offset to the filesystem you want to analyze. Run "mmls" on the dd file. Find the NTFS partition and use it's starting sector for the "-o" option (offset to the filesystem). Check the man page for more info. Barry -- /*************************************** Special Agent Barry J. Grundy NASA Office of Inspector General Computer Crimes Division Goddard Space Flight Center Code 190 Greenbelt Rd. Greenbelt, MD 20771 (301)286-3358 **************************************/ |
|
From: Jennifer S. <g33...@li...> - 2006-04-19 13:45:18
|
I should have added that there is another line in the error message. The e= ntire thing reads: [path where sleuthkit is]/sleuthkit-2.03//bin/fsstat: Error: not an NTFS fi= le system (invalid sector size) Incorrect file system type (-f ntfs) And the // before the "bin" isn't a typo. (Just in case that is weird.) Thanks again, gg --=20 _______________________________________________ Check out the latest SMS services @ http://www.linuxmail.org This allows you to send and receive SMS through your mailbox. Powered by Outblaze |
|
From: Jennifer S. <g33...@li...> - 2006-04-19 13:41:15
|
Thanks for the help with the path. I am now able to run sorter, but I am g= etting an error that I don't understand. I am running the following comman= d (from the /sleuthkit-2.03/ directory): perl ./bin/sorter -d [path where i want the information saved]/sorted -f nt= fs [path where the image is]/file.dd but I am getting the error "Incorrect file system type (-f ntfs) If I try running it without the -f flag at all, it says "Missing file syste= m type (and autodetect is not working)" I determined that it was ntfs from the results I got from Autopsy, but just= in case, I also tried other types in the command, all to no avail. Am I m= issing something? The .dd file that I am using is from the book _Real Digital Forensics_ (I n= eeded one to practice on), and it worked (from what I can tell) in Autopsy. I am pretty new to the Linux world of forensics tools, so I really apprecia= te the guidance. Thanks again for the help. And Brian, I have _File System Forensics_, too, I'm just not quite to that = level yet! Although I have used it for reference :) Thanks again, gg --=20 _______________________________________________ Check out the latest SMS services @ http://www.linuxmail.org This allows you to send and receive SMS through your mailbox. Powered by Outblaze |
|
From: farmer d. <far...@ya...> - 2006-04-18 19:36:36
|
--- Jennifer Smith <g33...@li...> wrote: > This is probably a newbie question, but what > directory should I be running "sorter" from? I was > trying to run it from the /Sleuthkit-2.03/ directory > and it is telling me "sorter: command not found" > Add '/usr/local/sleuthkit-2.03/bin' to your $PATH or symlink the binaries in '/usr/local/sleuthkit-2.03/bin' to a directory that's already in your path or use the fully-qualified path filename to the programs. Careful to not stomp any pre-existing programs with same name. regards, farmerdude http://www.forensicbootcd.com/ __________________________________________________ Do You Yahoo!? Tired of spam? Yahoo! Mail has the best spam protection around http://mail.yahoo.com |
|
From: J B <je...@ad...> - 2006-04-18 17:18:27
|
I'm very impressed by TSK's performance on my ibook. I recently upgraded it to panther 10.3, as high as my hardware can = handle. Previously, I was using linux and had wiped os9 off long ago. Firewire mass storage driver found my Tableau Write Blocker and put the = HD icon on my desktop. I dd'd the whole drive to image.dd. taking a look at the boot sector showed me that there was an ontrack = manager at the beginning, so, unlike most fat disks, OSX couldn't show = me this one. =20 I found the filesystem using sigfind 126 sectors in. I dd'd starting at = 126 to the end for a new "image126.dd" The problem arised when I wanted to mount the image.. no loop device = block devices in /dev... The mac disk utility can mount a filesystem image, but requires that it = have the ext .dmg. =20 Renamed to image126.dmg, mounted like a horse. Thanks again for writing the book _File System Forensic Analysis_, = Brian. -JB |
|
From: Jennifer S. <g33...@li...> - 2006-04-18 14:45:51
|
Thanks for the suggestion, "sorter" may be just what I need to try at this = point. This is probably a newbie question, but what directory should I be running = "sorter" from? I was trying to run it from the /Sleuthkit-2.03/ directory = and it is telling me "sorter: command not found" When I did a "locate sorter" is listed it in a few different places, so I w= asn't sure if I should be running it from somewhere else. I imagine a will end up writing some kind of script later on to do this alo= ng with other things, but I'd like to get this part working first! :) Thanks again for the help, gg --=20 _______________________________________________ Check out the latest SMS services @ http://www.linuxmail.org This allows you to send and receive SMS through your mailbox. Powered by Outblaze |
|
From: Brian C. <ca...@sl...> - 2006-04-18 13:00:26
|
Jennifer Smith wrote: > I have loaded the .dd into Autopsy with no problem, but once I go to the File Analysis screen, if I click on a file that is large (e.g. this happened with both a 23 MB file and a 400 MB file; the dd is 4 GB) it takes HOURS for the file to "load" into the browser to where I can click "Export" to copy the file out. > > Is there a way to mass export the files from either Sleuthkit or Autopsy? I was hoping to either have the option of selecting entire directories, or even all files. I don't expect checkboxes to select individual files (as cool as that would be!), but it is very time intensive to have to individually load and export each file. In Autopsy, there is no such feature. You can probably click on the "inode" address of a file and goto the Metadata view. From there you can save the file contents and this would save the time required to load the large file into the HTML browser (which do not like large files). But, that is not a mass extraction. You could script it in TSK, if you had the desire. brian |
|
From: youcef b. <ybi...@ya...> - 2006-04-17 21:46:13
|
Hi, try to use the sorter command. it will recover deleted files, sort them based on the file type and handle signature mismatch. I've noticed that running these tool using autopsy tend to spawn a lot of processes that doesnt seem to do anything useful. The only draw back of the command based approach is that you need to know what to pass in as parameters but there are artices on the informer that explain the sorter command in details. regards youcef ----- Original Message ---- From: Jennifer Smith <g33...@li...> To: sle...@li... Sent: Monday, 17 April, 2006 10:01:22 PM Subject: [sleuthkit-users] LONG loading time - Multiple Exports at a time possible? I have loaded the .dd into Autopsy with no problem, but once I go to the File Analysis screen, if I click on a file that is large (e.g. this happened with both a 23 MB file and a 400 MB file; the dd is 4 GB) it takes HOURS for the file to "load" into the browser to where I can click "Export" to copy the file out. Is there a way to mass export the files from either Sleuthkit or Autopsy? I was hoping to either have the option of selecting entire directories, or even all files. I don't expect checkboxes to select individual files (as cool as that would be!), but it is very time intensive to have to individually load and export each file. Pertinent Info: Fedora 3 Dual Core Xeon - too bad it doesn't actually use both processors :) Sleuthkit 2.03 Autopsy 2.06 Firefox 1.07 If you need more information, please let me know. Thanks, gg And to the developers, thanks for the hard work on a great program! -- _______________________________________________ Check out the latest SMS services @ http://www.linuxmail.org This allows you to send and receive SMS through your mailbox. Powered by Outblaze ------------------------------------------------------- This SF.Net email is sponsored by xPML, a groundbreaking scripting language that extends applications into web and mobile media. Attend the live webcast and join the prime developer group breaking into this new coding territory! http://sel.as-us.falkag.net/sel?cmd=lnk&kid0944&bid$1720&dat1642 _______________________________________________ sleuthkit-users mailing list https://lists.sourceforge.net/lists/listinfo/sleuthkit-users http://www.sleuthkit.org |
|
From: Jennifer S. <g33...@li...> - 2006-04-17 21:01:35
|
I have loaded the .dd into Autopsy with no problem, but once I go to the Fi= le Analysis screen, if I click on a file that is large (e.g. this happened = with both a 23 MB file and a 400 MB file; the dd is 4 GB) it takes HOURS fo= r the file to "load" into the browser to where I can click "Export" to copy= the file out. Is there a way to mass export the files from either Sleuthkit or Autopsy? = I was hoping to either have the option of selecting entire directories, or = even all files. I don't expect checkboxes to select individual files (as c= ool as that would be!), but it is very time intensive to have to individual= ly load and export each file. Pertinent Info: Fedora 3 Dual Core Xeon - too bad it doesn't actually use both processors :) Sleuthkit 2.03 Autopsy 2.06 Firefox 1.07 If you need more information, please let me know. Thanks, gg And to the developers, thanks for the hard work on a great program! --=20 _______________________________________________ Check out the latest SMS services @ http://www.linuxmail.org This allows you to send and receive SMS through your mailbox. Powered by Outblaze |
|
From: Brian C. <ca...@sl...> - 2006-04-14 12:33:11
|
Are you sure you are selecting the correct type (i.e. disk if the image is of the entire disk and partition if it is from a single partition)? Do you know what file system and partition types should be in the image? brian On Apr 12, 2006, at 4:38 PM, Michael Mannsberger wrote: > I'm trying to import a raw partition image. autopsy returns "The > image format type could not be determined for this image file". All > I can specify is location, type (disk or partition) and import method. |
|
From: Michael M. <mm4...@gm...> - 2006-04-12 20:38:58
|
I'm trying to import a raw partition image. autopsy returns "The image format type could not be determined for this image file". All I can specify is location, type (disk or partition) and import method. |
|
From: farmer d. <far...@ya...> - 2006-04-09 18:47:26
|
David, > I'm examining an 80 Gig hard drive. I started with > Knippix 3.6 and took > an initial hash with the drive inside the computer > and md5sum returned: > a4d83bac721f9e9cbef44a0f19c9f1d3 /dev/hda So you dropped in your KNOPPIX CD and made certain no file systems nor swap partitions (if applicable) were mounted or activated, and then you authenticated the physical device "/dev/hda" using 'md5sum' (Just want to make certain.)? > I installed the drive in another machine (Suse 9.3) > for examination and > md5sum returns: > ae319c49dbfc21fd2f392769083bed58 /dev/hdb So you then removed the suspect drive and dropped it into another system and received this hash value above using your Suse 9.3 installation? Again, absolutely certain your Suse didn't mount or activate anything on the suspect drive? > Using knoppix again, I get: > a4d83bac721f9e9cbef44a0f19c9f1d3 /dev/hda > And then you booted your Suse system with your same KNOPPIX CD and received the hash above, yes? Which kernel version for KNOPPIX CD (2.4 or 2.6)? Which kernel version for your Suse installation? You've confirmed these three findings by stepping through the same steps you took at least one more time? You're certain you authenticated the correct device node using your Suse installation? Let us know, until then we can only speculate. Odd size drive, authenticated the wrong device node, etc. regards, farmerdude http://www.forensicbootcd.com __________________________________________________ Do You Yahoo!? Tired of spam? Yahoo! Mail has the best spam protection around http://mail.yahoo.com |
|
From: Rich T. <te...@ap...> - 2006-04-08 22:41:31
|
I too, would verify it was actually on /dev/hdb on the Suse machine. Why would it be /dev/hda on the Suse exam machine (as indicated on the second Knoppix pass). I only use a firewire connection on my exam machine so its always /dev/sda (or b, c, d etc...). Did you boot with Knoppix on the host machine before pulling the drive? What did fdisk -l return on each machine??? I would also compare results from hdpram -I to ensure you are hitting the same drive. Detective David Vitkus <dv...@no...> wrote: Can anyone explain this one? I'm examining an 80 Gig hard drive. I started with Knippix 3.6 and took an initial hash with the drive inside the computer and md5sum returned: a4d83bac721f9e9cbef44a0f19c9f1d3 /dev/hda I installed the drive in another machine (Suse 9.3) for examination and md5sum returns: ae319c49dbfc21fd2f392769083bed58 /dev/hdb Using knoppix again, I get: a4d83bac721f9e9cbef44a0f19c9f1d3 /dev/hda Any thought would be appeciated. Thanks, -- David Vitkus Detective Northampton Police Department 29 Center St. Northampton, MA 01060 413-587-1133 (voice) 413-587-1137 (fax) ------------------------------------------------------- This SF.Net email is sponsored by xPML, a groundbreaking scripting language that extends applications into web and mobile media. Attend the live webcast and join the prime developer group breaking into this new coding territory! http://sel.as-us.falkag.net/sel?cmd=lnk&kid=110944&bid=241720&dat=121642 _______________________________________________ sleuthkit-users mailing list https://lists.sourceforge.net/lists/listinfo/sleuthkit-users http://www.sleuthkit.org |
|
From: Angus M. <an...@n-...> - 2006-04-08 16:57:49
|
Are you sure the drive in question was on hdb on the Suse machine ? What result do you get if you boot the Suse machine using Knoppix with the drive in question on hdb ? What sort of partitions and filesystems are on the disk ? Have you tried md5sum < /dev/hd[whatever] instead of using the filename. (It shouldn't matter, but it wouldn't hurt) On Sat Apr 8 13:31 , Detective David Vitkus <dv...@no...> sent: >Can anyone explain this one? > >I'm examining an 80 Gig hard drive. I started with Knippix 3.6 and took >an initial hash with the drive inside the computer and md5sum returned: >a4d83bac721f9e9cbef44a0f19c9f1d3 /dev/hda >I installed the drive in another machine (Suse 9.3) for examination and >md5sum returns: >ae319c49dbfc21fd2f392769083bed58 /dev/hdb >Using knoppix again, I get: >a4d83bac721f9e9cbef44a0f19c9f1d3 /dev/hda > >Any thought would be appeciated. > >Thanks, > >-- > >David Vitkus >Detective >Northampton Police Department >29 Center St. >Northampton, MA 01060 >413-587-1133 (voice) >413-587-1137 (fax) > > > >------------------------------------------------------- >This SF.Net email is sponsored by xPML, a groundbreaking scripting language >that extends applications into web and mobile media. Attend the live webcast >and join the prime developer group breaking into this new coding territory! >http://sel.as-us.falkag.net/sel?cmd=lnk&kid=110944&bid=241720&dat=121642 >_______________________________________________ >sleuthkit-users mailing list >https://lists.sourceforge.net/lists/listinfo/sleuthkit-users >http://www.sleuthkit.org |
|
From: Detective D. V. <dv...@no...> - 2006-04-08 12:26:47
|
Can anyone explain this one? I'm examining an 80 Gig hard drive. I started with Knippix 3.6 and took an initial hash with the drive inside the computer and md5sum returned: a4d83bac721f9e9cbef44a0f19c9f1d3 /dev/hda I installed the drive in another machine (Suse 9.3) for examination and md5sum returns: ae319c49dbfc21fd2f392769083bed58 /dev/hdb Using knoppix again, I get: a4d83bac721f9e9cbef44a0f19c9f1d3 /dev/hda Any thought would be appeciated. Thanks, -- David Vitkus Detective Northampton Police Department 29 Center St. Northampton, MA 01060 413-587-1133 (voice) 413-587-1137 (fax) |
|
From: farmer d. <far...@ya...> - 2006-04-08 05:08:57
|
Hi John, Beagle and webglimpse come to mind. Beagle is pretty sweet, 2.6 kernel only with GNOME desktop environment. Check out webglimpse - might be what you're looking for. regards, farmerdude www.forensicbootcd.com --- "John T. Hoffoss" <joh...@gm...> wrote: > Is anyone on this list aware of an open source > indexing search engine? I'm > looking for something along the lines of dtSearch > (which is what FTK's > indexed search is derived from) that I can use to > generate an index of case > files, and then perform string queries at a much > faster pace than if each > query has to read through the entirety of the > evidence files. > > Thanks. > > -- > John T. Hoffoss > __________________________________________________ Do You Yahoo!? Tired of spam? Yahoo! Mail has the best spam protection around http://mail.yahoo.com |
|
From: Brian C. <ca...@sl...> - 2006-04-07 14:32:09
|
Paul Bakker wrote: > For older versions of Autopsy/sleuthkit there is a "integrated" solution. > See: http://www.brainspark.nl > > For the latest versions a revision is in the making, but I'm still > waiting for some feedback from Brian. Yea, I have been the bottleneck. I just completed some changes that have been on the TODO list for quite a while and I will soon start to look at the large changes that have been submitted, such as this index search and some new file systems. brian |
|
From: Brian C. <ca...@sl...> - 2006-04-07 14:28:52
|
Are they both the same file system? Only Ext2 and Ext3 have the deleted time, so if the first file is on a different type then it will not have that time. brian Mario de Frutos Dieguez wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > Hi everyone! > > I'm new in this list and a n00b using forensics tools and making > forensics analysis. I hope that i learn a lot in this list! > > My question is: I have a deleted file that it inode had been realocated > but with the istat command i only obtain the following information: > > Inode Times: > Accessed: Tue Mar 21 00:00:15 2006 > File Modified: Mon Mar 20 12:08:04 2006 > Inode Modified: Mon Mar 20 12:08:04 2006 > > In other unllocated inodes i have the following information: > > Inode Times: > Accessed: Wed Feb 8 00:00:15 2006 > File Modified: Thu Feb 16 18:41:37 2006 > Inode Modified: Thu Feb 16 18:41:37 2006 > Deleted: Thu Feb 16 18:41:37 2006 > > How can i obtain the "deleted" info in the first inode? > > Thank you and sorry for my "bad english" > -----BEGIN PGP SIGNATURE----- > Version: GnuPG v1.4.2.2 (GNU/Linux) > Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org > > iD8DBQFENNN9bPPtxT8v/3wRAh0vAJ9QQYUBS2t1BZSdOaIRJ6dAiLaOLwCfcny1 > xwAtNE9KpYz6wfEv2KThsmY= > =OrR/ > -----END PGP SIGNATURE----- > > > ------------------------------------------------------- > This SF.Net email is sponsored by xPML, a groundbreaking scripting language > that extends applications into web and mobile media. Attend the live webcast > and join the prime developer group breaking into this new coding territory! > http://sel.as-us.falkag.net/sel?cmd=lnk&kid=110944&bid=241720&dat=121642 > _______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org |
|
From: Paul B. <p.j...@br...> - 2006-04-06 20:13:07
|
For older versions of Autopsy/sleuthkit there is a "integrated" solution. See: http://www.brainspark.nl For the latest versions a revision is in the making, but I'm still waiting for some feedback from Brian.. Regards, Paul John T. Hoffoss wrote: >Is anyone on this list aware of an open source indexing search engine? I'm >looking for something along the lines of dtSearch (which is what FTK's >indexed search is derived from) that I can use to generate an index of case >files, and then perform string queries at a much faster pace than if each >query has to read through the entirety of the evidence files. > >Thanks. > >-- >John T. Hoffoss > > |