sleuthkit-users Mailing List for The Sleuth Kit (Page 172)
Brought to you by:
carrier
You can subscribe to this list here.
2002 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
(6) |
Aug
|
Sep
(11) |
Oct
(5) |
Nov
(4) |
Dec
|
---|---|---|---|---|---|---|---|---|---|---|---|---|
2003 |
Jan
(1) |
Feb
(20) |
Mar
(60) |
Apr
(40) |
May
(24) |
Jun
(28) |
Jul
(18) |
Aug
(27) |
Sep
(6) |
Oct
(14) |
Nov
(15) |
Dec
(22) |
2004 |
Jan
(34) |
Feb
(13) |
Mar
(28) |
Apr
(23) |
May
(27) |
Jun
(26) |
Jul
(37) |
Aug
(19) |
Sep
(20) |
Oct
(39) |
Nov
(17) |
Dec
(9) |
2005 |
Jan
(45) |
Feb
(43) |
Mar
(66) |
Apr
(36) |
May
(19) |
Jun
(64) |
Jul
(10) |
Aug
(11) |
Sep
(35) |
Oct
(6) |
Nov
(4) |
Dec
(13) |
2006 |
Jan
(52) |
Feb
(34) |
Mar
(39) |
Apr
(39) |
May
(37) |
Jun
(15) |
Jul
(13) |
Aug
(48) |
Sep
(9) |
Oct
(10) |
Nov
(47) |
Dec
(13) |
2007 |
Jan
(25) |
Feb
(4) |
Mar
(2) |
Apr
(29) |
May
(11) |
Jun
(19) |
Jul
(13) |
Aug
(15) |
Sep
(30) |
Oct
(12) |
Nov
(10) |
Dec
(13) |
2008 |
Jan
(2) |
Feb
(54) |
Mar
(58) |
Apr
(43) |
May
(10) |
Jun
(27) |
Jul
(25) |
Aug
(27) |
Sep
(48) |
Oct
(69) |
Nov
(55) |
Dec
(43) |
2009 |
Jan
(26) |
Feb
(36) |
Mar
(28) |
Apr
(27) |
May
(55) |
Jun
(9) |
Jul
(19) |
Aug
(16) |
Sep
(15) |
Oct
(17) |
Nov
(70) |
Dec
(21) |
2010 |
Jan
(56) |
Feb
(59) |
Mar
(53) |
Apr
(32) |
May
(25) |
Jun
(31) |
Jul
(36) |
Aug
(11) |
Sep
(37) |
Oct
(19) |
Nov
(23) |
Dec
(6) |
2011 |
Jan
(21) |
Feb
(20) |
Mar
(30) |
Apr
(30) |
May
(74) |
Jun
(50) |
Jul
(34) |
Aug
(34) |
Sep
(12) |
Oct
(33) |
Nov
(10) |
Dec
(8) |
2012 |
Jan
(23) |
Feb
(57) |
Mar
(26) |
Apr
(14) |
May
(27) |
Jun
(27) |
Jul
(60) |
Aug
(88) |
Sep
(13) |
Oct
(36) |
Nov
(97) |
Dec
(85) |
2013 |
Jan
(60) |
Feb
(24) |
Mar
(43) |
Apr
(32) |
May
(22) |
Jun
(38) |
Jul
(51) |
Aug
(50) |
Sep
(76) |
Oct
(65) |
Nov
(25) |
Dec
(30) |
2014 |
Jan
(19) |
Feb
(41) |
Mar
(43) |
Apr
(28) |
May
(61) |
Jun
(12) |
Jul
(10) |
Aug
(37) |
Sep
(76) |
Oct
(31) |
Nov
(41) |
Dec
(12) |
2015 |
Jan
(33) |
Feb
(28) |
Mar
(53) |
Apr
(22) |
May
(29) |
Jun
(20) |
Jul
(15) |
Aug
(17) |
Sep
(52) |
Oct
(3) |
Nov
(18) |
Dec
(21) |
2016 |
Jan
(20) |
Feb
(8) |
Mar
(21) |
Apr
(7) |
May
(13) |
Jun
(35) |
Jul
(34) |
Aug
(11) |
Sep
(14) |
Oct
(22) |
Nov
(31) |
Dec
(23) |
2017 |
Jan
(20) |
Feb
(7) |
Mar
(5) |
Apr
(6) |
May
(6) |
Jun
(22) |
Jul
(11) |
Aug
(16) |
Sep
(8) |
Oct
(1) |
Nov
(1) |
Dec
(1) |
2018 |
Jan
|
Feb
|
Mar
(16) |
Apr
(2) |
May
(6) |
Jun
(5) |
Jul
|
Aug
(2) |
Sep
(4) |
Oct
|
Nov
(16) |
Dec
(13) |
2019 |
Jan
|
Feb
(1) |
Mar
(25) |
Apr
(9) |
May
(2) |
Jun
(1) |
Jul
(1) |
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
2020 |
Jan
(2) |
Feb
|
Mar
(1) |
Apr
|
May
(1) |
Jun
(3) |
Jul
(2) |
Aug
|
Sep
|
Oct
(5) |
Nov
|
Dec
|
2021 |
Jan
|
Feb
|
Mar
(1) |
Apr
|
May
|
Jun
(4) |
Jul
(1) |
Aug
|
Sep
(1) |
Oct
|
Nov
(1) |
Dec
|
2022 |
Jan
|
Feb
(2) |
Mar
|
Apr
|
May
(2) |
Jun
|
Jul
(3) |
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
2023 |
Jan
(2) |
Feb
|
Mar
(1) |
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
(1) |
Nov
|
Dec
|
2024 |
Jan
|
Feb
(3) |
Mar
|
Apr
(1) |
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
2025 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
(1) |
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
From: Aaron S. <aa...@se...> - 2006-01-31 18:12:18
|
I've recombined Linux raids with varying degrees of success. It's certainly one of the big reasons I use Linux's software raid -- most hardware raids just don't give you even a glimmer of hope here. An important detail is to use the appropriate options to stop the md system from automatically resyncing your raid; if you get the options wrong the first time and then it tries to resync, it's all over. A lot of info out there is way out of date. Lots of work MD has taken place in the 2.6 kernel. This page looks fairly recent: http://software.cfht.hawaii.edu/linuxpc/RAID_recovery.html Aaron On Tue, 2006-01-31 at 12:49 -0500, Brian Carrier wrote: > I have tried to recreate RAIDs before using loopback and the RAID > support in the Linux kernel (similar to your raiddev example), but I > was unsuccessful. I don't remember the details anymore because I'm > in the middle of a move and all of my stuff is packed up. But, it > may work in newer versions of the kernel. > > brian > > > > On Jan 29, 2006, at 10:46 PM, J B wrote: > > > Suppose you have a raid of 8 9GIG disks. > > You have imaged each disk using dd so that you have diskimg0 ... > > diskimg7 > > > > What's the best way to mount this group of images in software so > > that you > > can then operate on it using TSK? I assume it involves mounting a > > loopback > > device.. > > > > it's seems like you'd want to use /dev/loopX in raiddev per disk > > > > but I'm not sure that: > > mount -ro /evidence/diskimg0 /whocareswhere -t whatevertype -o > > loop=/dev/loop0, blocksize= (CHUNKSIZE?) > > would be appropriate. Seems like you're mounting the image > > unneccesarily leaving the mounted stub at /whocareswhere when all > > you really want is to tie loop0 to the image... > > > > raiddev /dev/md0 > > raid-level linear > > nr-raid-disks 2 > > chunk-size 32 > > persistent-superblock 1 > > device /dev/loop0 > > raid-disk 0 > > device /dev/loop1 > > raid-disk 1 > > > > > > Just curious, > > > > -Jessop > > |
From: Brian C. <ca...@sl...> - 2006-01-31 17:52:29
|
I don't know of any comprehensive tools that take a file name and search the system for all references to it. File system tools like TSK / Autopsy (and others) will give you the last modified, accessed, created, changed, etc times, but that is not a full history. It won't tell you which app did the creation or modification or when each app printed it though. You can make timelines with TSK and Autopsy as well, but again this is for only the last times and not a "complete history". The complete history is not saved on most systems. brian On Jan 30, 2006, at 12:53 AM, sr...@nm... wrote: > hi, > thanks for replying. > i mean i want a tool that can give me the > 1)history of the file(when the file is created,modified,printed,edited > anything that is useful) > 2)time analysis(i want the tool to display the time it is > created,modified,printed,edited anything that is useful) > > i mean i need the complete history of the file. > > please let me know as soon as possible. > > thanks again for replying. > > > > ------------------------------------------------------- > This SF.net email is sponsored by: Splunk Inc. Do you grep through > log files > for problems? Stop! Download the new AJAX search engine that makes > searching your log files as easy as surfing the web. DOWNLOAD > SPLUNK! > http://sel.as-us.falkag.net/sel? > cmd_______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org |
From: Brian C. <ca...@sl...> - 2006-01-31 17:49:38
|
I have tried to recreate RAIDs before using loopback and the RAID support in the Linux kernel (similar to your raiddev example), but I was unsuccessful. I don't remember the details anymore because I'm in the middle of a move and all of my stuff is packed up. But, it may work in newer versions of the kernel. brian On Jan 29, 2006, at 10:46 PM, J B wrote: > Suppose you have a raid of 8 9GIG disks. > You have imaged each disk using dd so that you have diskimg0 ... > diskimg7 > > What's the best way to mount this group of images in software so > that you > can then operate on it using TSK? I assume it involves mounting a > loopback > device.. > > it's seems like you'd want to use /dev/loopX in raiddev per disk > > but I'm not sure that: > mount -ro /evidence/diskimg0 /whocareswhere -t whatevertype -o > loop=/dev/loop0, blocksize= (CHUNKSIZE?) > would be appropriate. Seems like you're mounting the image > unneccesarily leaving the mounted stub at /whocareswhere when all > you really want is to tie loop0 to the image... > > raiddev /dev/md0 > raid-level linear > nr-raid-disks 2 > chunk-size 32 > persistent-superblock 1 > device /dev/loop0 > raid-disk 0 > device /dev/loop1 > raid-disk 1 > > > Just curious, > > -Jessop > > > > > ------------------------------------------------------- > This SF.net email is sponsored by: Splunk Inc. Do you grep through > log files > for problems? Stop! Download the new AJAX search engine that makes > searching your log files as easy as surfing the web. DOWNLOAD > SPLUNK! > http://sel.as-us.falkag.net/sel? > cmd=lnk&kid=103432&bid=230486&dat=121642 > _______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org |
From: Brian C. <ca...@sl...> - 2006-01-31 17:46:15
|
When you added the partitions for the USB drive image (pri.img), they were imported as a raw format. This occurs when the specific file system type can not be determined. Based on the layout of the partitions, it looks like the partition table is screwed up because the partitions seem to overlap each other. If the partition table is correct and a file system exists in the partition, Autopsy will detect it and show the file system in the timeline listing. brian On Jan 27, 2006, at 6:51 PM, Aleksander Lavrih wrote: > In Autopsy I want to Create Data File, but there is no images to > select > from. Can you help me find my mistake? Image is from USB key. Autopsy > 2.06. > > > > > 1.____________________________________________________________________ > ___ > Here we will process the file system images, collect the temporal > data, > and save the data to a single file. > > 1. Select one or more of the following images to collect data from: > > 2. Select the data types to gather: > > > > Allocated > Files > > Unallocated > Files > > Unallocated > Meta Data > Structures > > 3. Enter name of output file (body): > output/ > > 4. Generate MD5 Value? > > > 2_____________________________________________________________________ > > Case Gallery > Host Gallery > Host Manager (Current > Mode) > > mount > name > fs type > > > disk > prvi.img-disk > raw > details > > raw > prvi.img-538989391-1937352302 > raw > details > > raw > prvi.img-1330184202-1869160489 > raw > details > > raw > prvi.img-1394627663-1394648999 > raw > details > > raw > prvi.img-1919950958-2464388050 > raw > details > > > > > > > > > > > > > ------------------------------------------------------- > This SF.net email is sponsored by: Splunk Inc. Do you grep through > log files > for problems? Stop! Download the new AJAX search engine that makes > searching your log files as easy as surfing the web. DOWNLOAD > SPLUNK! > http://sel.as-us.falkag.net/sel? > cmd=lnk&kid=103432&bid=230486&dat=121642 > _______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org |
From: <sr...@nm...> - 2006-01-30 05:53:59
|
hi, thanks for replying. i mean i want a tool that can give me the 1)history of the file(when the file is created,modified,printed,edited anything that is useful) 2)time analysis(i want the tool to display the time it is created,modified,printed,edited anything that is useful) i mean i need the complete history of the file. please let me know as soon as possible. thanks again for replying. |
From: farmer d. <far...@ya...> - 2006-01-30 03:53:40
|
With ext3 you will have to carve for headers/footers -OR- search for what you're looking for (IE, a key word or phrase, hopefully unique :) ) due to how deletion is handled. regards, farmerdude --- "te...@me..." <te...@me...> wrote: > Hello, > I think my problem is that the files were deleted on > an EXT3 filesystem, it's certainly why icat doesn't > find anything. > > farmer dude wrote: > > Hi, > > > > Your success will depend largely on the file > system > > type the deleted files reside on. What type? > > > > Using The Sleuth Kit you can use 'icat' to > undelete > > deleted files. > > > > Other utilities are available that can assist, > > depending upon the file system type. > > > > regards, > > > > farmerdude > > > > THE FARMER'S BOOT CD > > > > ------------------------------------------------------- > This SF.net email is sponsored by: Splunk Inc. Do > you grep through log files > for problems? Stop! Download the new AJAX search > engine that makes > searching your log files as easy as surfing the > web. DOWNLOAD SPLUNK! > http://sel.as-us.falkag.net/sel?cmd=lnk&kid=103432&bid=230486&dat=121642 > _______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org > __________________________________________________ Do You Yahoo!? Tired of spam? Yahoo! Mail has the best spam protection around http://mail.yahoo.com |
From: J B <je...@ad...> - 2006-01-30 03:46:11
|
Suppose you have a raid of 8 9GIG disks. You have imaged each disk using dd so that you have diskimg0 ... diskimg7 What's the best way to mount this group of images in software so that you can then operate on it using TSK? I assume it involves mounting a loopback device.. it's seems like you'd want to use /dev/loopX in raiddev per disk but I'm not sure that: mount -ro /evidence/diskimg0 /whocareswhere -t whatevertype -o loop=/dev/loop0, blocksize= (CHUNKSIZE?) would be appropriate. Seems like you're mounting the image unneccesarily leaving the mounted stub at /whocareswhere when all you really want is to tie loop0 to the image... raiddev /dev/md0 raid-level linear nr-raid-disks 2 chunk-size 32 persistent-superblock 1 device /dev/loop0 raid-disk 0 device /dev/loop1 raid-disk 1 Just curious, -Jessop |
From: farmer d. <far...@ya...> - 2006-01-30 01:13:20
|
Hello Jessop, If you budget allows, then hands-down SMART Linux (www.asrdata2.com). Everything has done for you. Forensically designed and optimized. Slackware Linux makes a great platform as it is very clean, lean, and uses vanilla kernel from www.kernel.org. I never recommend RH/FC for Data Forensics work. regards, farmerdude --- J B <je...@ad...> wrote: > I'm having trouble finding my ultrablock under > Fedora 4. I think this started when I "yum update"ed > everything. I was able to dd from it before, then I > found the problem with 'fsstat' and updated hoping > it would fix it. Brian fixed it for me, but now I > think my update caused problems with reading the > ultrablock. > > > If I restart, I can insert my flash drive and it > works. When I power on the UltraBlock(usb mass > storage) dmesg says > > > > SELinux: initialized (dev sdb1, type vfat), uses > genfs_contexts > usb 2-1: new full speed USB device using ohci_hcd > and address 2 > scsi1 : SCSI emulation for USB Mass Storage devices > usb-storage: device found at 2 > usb-storage: waiting for device to settle before > scanning > Vendor: QUANTUM Model: FIREBALLlct20 20 Rev: > APL. > Type: Direct-Access ANSI > SCSI revision: 04 > SCSI device sdc: 39876480 512-byte hdwr sectors > (20417 MB) > sdc: assuming drive cache: write through > SCSI device sdc: 39876480 512-byte hdwr sectors > (20417 MB) > sdc: assuming drive cache: write through > sdc: sdc1 sdc2 > Attached scsi disk sdc at scsi1, channel 0, id 0, > lun 0 > Attached scsi generic sg2 at scsi1, channel 0, id 0, > lun 0, type 0 > usb 2-1: reset full speed USB device using ohci_hcd > and address 2 > usb 2-1: device descriptor read/64, error -110 > usb 2-1: device descriptor read/64, error -110 > usb 2-1: reset full speed USB device using ohci_hcd > and address 2 > usb 2-1: device descriptor read/64, error -110 > usb 2-1: device descriptor read/64, error -110 > usb 2-1: reset full speed USB device using ohci_hcd > and address 2 > usb 2-1: device descriptor read/8, error -110 > usb 2-1: device descriptor read/8, error -110 > usb 2-1: reset full speed USB device using ohci_hcd > and address 2 > usb 2-1: device descriptor read/8, error -110 > usb 2-1: device descriptor read/8, error -110 > usb 2-1: USB disconnect, address 2 > scsi: Device offlined - not ready after error > recovery: host 1 channel 0 id 0 lun 0 > scsi1 (0:0): rejecting I/O to offline device > scsi1 (0:0): rejecting I/O to offline device > scsi1 (0:0): rejecting I/O to offline device > sd 1:0:0:0: SCSI error: return code = 0x10000 > end_request: I/O error, dev sdc, sector 0 > Buffer I/O error on device sdc, logical block 0 > scsi1 (0:0): rejecting I/O to offline device > Buffer I/O error on device sdc, logical block 1 > Buffer I/O error on device sdc, logical block 2 > Buffer I/O error on device sdc, logical block 3 > Buffer I/O error on device sdc, logical block 4 > Buffer I/O error on device sdc, logical block 5 > Buffer I/O error on device sdc, logical block 6 > Buffer I/O error on device sdc, logical block 7 > scsi1 (0:0): rejecting I/O to offline device > Buffer I/O error on device sdc, logical block 0 > > any ideas? What distro gives the rest of you the > least problems? Fedora hasn't been good news for > me. > > Thanks > -Jessop > __________________________________________________ Do You Yahoo!? Tired of spam? Yahoo! Mail has the best spam protection around http://mail.yahoo.com |
From: farmer d. <far...@ya...> - 2006-01-30 01:02:38
|
Hi, Since you posted on The Sleuth Kit list I figure you're looking for a *nix-based tool (or tools) to find file metadata (metadata structures found in PDF, DOC, etc.)? On the current version of my boot CD I have tools to dump metadata from PDF documents. The data obtained is dependent upon the software used to write the file of course. Mileage will vary with metadata. On the next release I will have included support for MS Word documents (already complete in testing environment, just in queue for next release of CD) as well. PERL can assist you in finding metadata within certain file types. Any file types specifically you're looking for? regards, farmerdude http://www.farmerdude.com/farmercd.html --- sr...@nm... wrote: > hello, > could any of you tell me about metadata analysis and > the tools that help > in finding the metadata. > i want to know about some tools that help me in > finding the metadata that > is hidden in the files, and also some tools to > remove metadata. > > > > ------------------------------------------------------- > This SF.net email is sponsored by: Splunk Inc. Do > you grep through log files > for problems? Stop! Download the new AJAX search > engine that makes > searching your log files as easy as surfing the > web. DOWNLOAD SPLUNK! > http://sel.as-us.falkag.net/sel?cmd=lnk&kid3432&bid#0486&dat1642 > _______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org > __________________________________________________ Do You Yahoo!? Tired of spam? Yahoo! Mail has the best spam protection around http://mail.yahoo.com |
From: J B <je...@ad...> - 2006-01-29 18:33:57
|
Interestingly, I formatted the 500MB disk that works from vfat to ntfs using the write-enabled UltraBlock in windows XP. Fired it up in fedora, and Fedora at least -tried- to mount that one - the icon showed up and everything. Problem is I didn't have NTFS module loaded (nor is it installed right now). So, that explains that, but it doesn't explain why the other drive crashes the whole usb storage subsytem when the usb-ide bridge is started up with it. There have been compatibility issues with DI (Tableau) products in the past, so maybe they have a firmware update. |
From: Barry J. G. <bg...@im...> - 2006-01-29 18:17:49
|
On Sun, 2006-01-29 at 17:42 +0000, youcef bichbiche wrote: > Hi, > I am not sure what you mean by metadata in your > postings. I believe the OP is refering to the sort of "metadata" that resides within "office" documents. Things like print and edit history, user history, etc. Check out http://smartpctools.com/metadata for an example tool for this. Open Office gives you the ability to view some of the metadata as well, along with the "recover text from any file" option in the MS products. -- /*************************************** Special Agent Barry J. Grundy NASA Office of Inspector General Computer Crimes Division Goddard Space Flight Center Code 190 Greenbelt Rd. Greenbelt, MD 20771 (301)286-3358 **************************************/ |
From: youcef b. <ybi...@ya...> - 2006-01-29 17:42:16
|
Hi, I am not sure what you mean by metadata in your postings. If you mean file and directory metadata then TSK and autopsy can help you in finding this information. But you request for removing metadata puzzles me. Are you trying to investigate an image, in which case you dont need and shouldnt not remove any data from the exhibit. otherwise, if you meant a tool that would delete files and their corresponding metadata then can you be more explicit about the environment you are operatinog on. regards youcef --- sr...@nm... wrote: > hello, > could any of you tell me about metadata analysis and > the tools that help > in finding the metadata. > i want to know about some tools that help me in > finding the metadata that > is hidden in the files, and also some tools to > remove metadata. > > > > ------------------------------------------------------- > This SF.net email is sponsored by: Splunk Inc. Do > you grep through log files > for problems? Stop! Download the new AJAX search > engine that makes > searching your log files as easy as surfing the > web. DOWNLOAD SPLUNK! > http://sel.as-us.falkag.net/sel?cmd=lnk&kid3432&bid#0486&dat1642 > _______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org > ___________________________________________________________ Yahoo! Photos NEW, now offering a quality print service from just 8p a photo http://uk.photos.yahoo.com |
From: <sr...@nm...> - 2006-01-29 05:17:22
|
hello, could any of you tell me about metadata analysis and the tools that help in finding the metadata. i want to know about some tools that help me in finding the metadata that is hidden in the files, and also some tools to remove metadata. |
From: <sr...@nm...> - 2006-01-29 05:15:39
|
hello, could any of you tell me about metadata analysis and the tools that help in finding the metadata. i want to know about some tools that help me in finding the metadata that is hidden in the files, and also some tools to remove metadata. |
From: J B <je...@ad...> - 2006-01-29 03:16:58
|
Sorry, I realized I shouldn't have posted that question here. To update, I found the the problem was the HD was ntfs and fedora's mass = storage seems to assume it's vfat. I'm talking to the fedora people = about it. -Jessop |
From: J B <je...@ad...> - 2006-01-29 02:41:07
|
I'm having trouble finding my ultrablock under Fedora 4. I think this = started when I "yum update"ed everything. I was able to dd from it = before, then I found the problem with 'fsstat' and updated hoping it = would fix it. Brian fixed it for me, but now I think my update caused = problems with reading the ultrablock. If I restart, I can insert my flash drive and it works. When I power = on the UltraBlock(usb mass storage) dmesg says SELinux: initialized (dev sdb1, type vfat), uses genfs_contexts usb 2-1: new full speed USB device using ohci_hcd and address 2 scsi1 : SCSI emulation for USB Mass Storage devices usb-storage: device found at 2 usb-storage: waiting for device to settle before scanning Vendor: QUANTUM Model: FIREBALLlct20 20 Rev: APL. Type: Direct-Access ANSI SCSI revision: 04 SCSI device sdc: 39876480 512-byte hdwr sectors (20417 MB) sdc: assuming drive cache: write through SCSI device sdc: 39876480 512-byte hdwr sectors (20417 MB) sdc: assuming drive cache: write through sdc: sdc1 sdc2 Attached scsi disk sdc at scsi1, channel 0, id 0, lun 0 Attached scsi generic sg2 at scsi1, channel 0, id 0, lun 0, type 0 usb 2-1: reset full speed USB device using ohci_hcd and address 2 usb 2-1: device descriptor read/64, error -110 usb 2-1: device descriptor read/64, error -110 usb 2-1: reset full speed USB device using ohci_hcd and address 2 usb 2-1: device descriptor read/64, error -110 usb 2-1: device descriptor read/64, error -110 usb 2-1: reset full speed USB device using ohci_hcd and address 2 usb 2-1: device descriptor read/8, error -110 usb 2-1: device descriptor read/8, error -110 usb 2-1: reset full speed USB device using ohci_hcd and address 2 usb 2-1: device descriptor read/8, error -110 usb 2-1: device descriptor read/8, error -110 usb 2-1: USB disconnect, address 2 scsi: Device offlined - not ready after error recovery: host 1 channel 0 = id 0 lun 0 scsi1 (0:0): rejecting I/O to offline device scsi1 (0:0): rejecting I/O to offline device scsi1 (0:0): rejecting I/O to offline device sd 1:0:0:0: SCSI error: return code =3D 0x10000 end_request: I/O error, dev sdc, sector 0 Buffer I/O error on device sdc, logical block 0 scsi1 (0:0): rejecting I/O to offline device Buffer I/O error on device sdc, logical block 1 Buffer I/O error on device sdc, logical block 2 Buffer I/O error on device sdc, logical block 3 Buffer I/O error on device sdc, logical block 4 Buffer I/O error on device sdc, logical block 5 Buffer I/O error on device sdc, logical block 6 Buffer I/O error on device sdc, logical block 7 scsi1 (0:0): rejecting I/O to offline device Buffer I/O error on device sdc, logical block 0 any ideas? What distro gives the rest of you the least problems? = Fedora hasn't been good news for me. Thanks -Jessop |
From: Aleksander L. <ale...@si...> - 2006-01-27 23:51:38
|
In Autopsy I want to Create Data File, but there is no images to select from. Can you help me find my mistake? Image is from USB key. Autopsy 2.06. 1._______________________________________________________________________ Here we will process the file system images, collect the temporal data, and save the data to a single file. 1. Select one or more of the following images to collect data from: 2. Select the data types to gather: Allocated Files Unallocated Files Unallocated Meta Data Structures 3. Enter name of output file (body): output/ 4. Generate MD5 Value? 2_____________________________________________________________________ Case Gallery Host Gallery Host Manager (Current Mode) mount name fs type disk prvi.img-disk raw details raw prvi.img-538989391-1937352302 raw details raw prvi.img-1330184202-1869160489 raw details raw prvi.img-1394627663-1394648999 raw details raw prvi.img-1919950958-2464388050 raw details |
From: <te...@me...> - 2006-01-25 07:36:58
|
Hello, I think my problem is that the files were deleted on an EXT3 filesystem, it's certainly why icat doesn't find anything. farmer dude wrote: > Hi, > > Your success will depend largely on the file system > type the deleted files reside on. What type? > > Using The Sleuth Kit you can use 'icat' to undelete > deleted files. > > Other utilities are available that can assist, > depending upon the file system type. > > regards, > > farmerdude > > THE FARMER'S BOOT CD |
From: farmer d. <far...@ya...> - 2006-01-25 00:24:17
|
Hi, Your success will depend largely on the file system type the deleted files reside on. What type? Using The Sleuth Kit you can use 'icat' to undelete deleted files. Other utilities are available that can assist, depending upon the file system type. regards, farmerdude THE FARMER'S BOOT CD --- "te...@me..." <te...@me...> wrote: > Hello everybody, > I'm new to sleuthkit,and I've got a problem which > might seem very basic to most og you but I can't > resolve it : > I recently burned some files from my hard-disk to a > CD / RW, then I deleted these files from my > hard-disk. > When I tried to read the CD, there seems to be > nothing on it. > I wasn't able to dd an image of the cd, so I can't > recover my files this way. > Then I launched autopsy on my hard-disk. Using File > analysis, I can see all the deleted files, but now, > I don't know how > to recover them. I don't want to use the sorter tool > from autopsy because I don't have enough free space > to copy all the > recovered files, only enough for the 700Mb of my > deleted files. > I would like to know what is the simple procedure to > recover one by one a few files which seems I good > state to recover > (as the partition where I deleted files wasn't > mounted since the deletion). > > > ------------------------------------------------------- > This SF.net email is sponsored by: Splunk Inc. Do > you grep through log files > for problems? Stop! Download the new AJAX search > engine that makes > searching your log files as easy as surfing the > web. DOWNLOAD SPLUNK! > http://sel.as-us.falkag.net/sel?cmd=lnk&kid=103432&bid=230486&dat=121642 > _______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org > __________________________________________________ Do You Yahoo!? Tired of spam? Yahoo! Mail has the best spam protection around http://mail.yahoo.com |
From: youcef b. <ybi...@ya...> - 2006-01-25 00:11:02
|
Hi, I think the answer was already highlighted. Issue fls on your drive and then looking at the file of interest, pick their inode number from the report generatd by fls command and issue icat against them. regards youcef --- "te...@me..." <te...@me...> wrote: > Thanks very much for your answer. > > In my case I think that it's not mandatory to use > another computer, because the deleted files were > placed on the third > harddrive of my computer (/dev/hdd1), so I removed > it from fstab so it should not be mounted nor armed > after. > I've got enough space on other partitions on other > drives to copy the recovered files (about 700 Mb : > one CD) but not > enough to put the whole output from sorter which > could reach the size of the entire drive (10Go). > I just wanted to know if there was a script to > recover deleted files with no particular problems : > I just made rm on the > files then shutdown the computer, and didn't mounted > this partition since, I know the names of the files > and their > sizes, there are only 7 or 8 to recover. So for > someone used to it it should be trivial to get them > back no ? > > Fra...@ps... wrote: > > > > tech; > > > > my suggestion would be to download (on a different > computer) F.I.R.E. > > (it's got a copy of Sleuthkit and Autopsy and it's > linux. Burn the iso > > onto a CD, it's bootable. Insert a 1gig (at best) > thumb drive into the > > usbport before booting, boot the computer with the > deleted files using > > FIRE. dd the space which contains the files or > use the Autopsy browser > > to move the files to the thumb drive. I make it > sound simple but if > > you've used Autopsy this should be pretty simple. > Keep the FIRE CD > > handy as it's a great tool to use. > > > > Frank Kenisky IV, CISSP, CISA, CISM > > Information Technical Security Specialist > > (210) 301-6433 - (210) 887-6985 > > > > > > *"te...@me..." <te...@me...>* > > Sent by: > sle...@li... > > > > 01/24/2006 04:56 AM > > > > > > To > > sle...@li... > > cc > > > > Subject > > [sleuthkit-users] How to simply undelete files ? > > > > > > > > > > > > > > > > > > Hello everybody, > > I'm new to sleuthkit,and I've got a problem which > might seem very basic > > to most og you but I can't resolve it : > > I recently burned some files from my hard-disk to > a CD / RW, then I > > deleted these files from my hard-disk. > > When I tried to read the CD, there seems to be > nothing on it. > > I wasn't able to dd an image of the cd, so I can't > recover my files this > > way. > > Then I launched autopsy on my hard-disk. Using > File analysis, I can see > > all the deleted files, but now, I don't know how > > to recover them. I don't want to use the sorter > tool from autopsy > > because I don't have enough free space to copy all > the > > recovered files, only enough for the 700Mb of my > deleted files. > > I would like to know what is the simple procedure > to recover one by one > > a few files which seems I good state to recover > > (as the partition where I deleted files wasn't > mounted since the deletion). > > > > > > > ------------------------------------------------------- > > This SF.net email is sponsored by: Splunk Inc. Do > you grep through log files > > for problems? Stop! Download the new AJAX search > engine that makes > > searching your log files as easy as surfing the > web. DOWNLOAD SPLUNK! > > > http://sel.as-us.falkag.net/sel?cmd=lnk&kid=103432&bid=230486&dat=121642 > > _______________________________________________ > > sleuthkit-users mailing list > > > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > > http://www.sleuthkit.org > > > > > ------------------------------------------------------- > This SF.net email is sponsored by: Splunk Inc. Do > you grep through log files > for problems? Stop! Download the new AJAX search > engine that makes > searching your log files as easy as surfing the > web. DOWNLOAD SPLUNK! > http://sel.as-us.falkag.net/sel?cmd=lnk&kid=103432&bid=230486&dat=121642 > _______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org > ___________________________________________________________ To help you stay safe and secure online, we've developed the all new Yahoo! Security Centre. http://uk.security.yahoo.com |
From: <te...@me...> - 2006-01-24 16:14:07
|
Thanks very much for your answer. In my case I think that it's not mandatory to use another computer, because the deleted files were placed on the third harddrive of my computer (/dev/hdd1), so I removed it from fstab so it should not be mounted nor armed after. I've got enough space on other partitions on other drives to copy the recovered files (about 700 Mb : one CD) but not enough to put the whole output from sorter which could reach the size of the entire drive (10Go). I just wanted to know if there was a script to recover deleted files with no particular problems : I just made rm on the files then shutdown the computer, and didn't mounted this partition since, I know the names of the files and their sizes, there are only 7 or 8 to recover. So for someone used to it it should be trivial to get them back no ? Fra...@ps... wrote: > > tech; > > my suggestion would be to download (on a different computer) F.I.R.E. > (it's got a copy of Sleuthkit and Autopsy and it's linux. Burn the iso > onto a CD, it's bootable. Insert a 1gig (at best) thumb drive into the > usbport before booting, boot the computer with the deleted files using > FIRE. dd the space which contains the files or use the Autopsy browser > to move the files to the thumb drive. I make it sound simple but if > you've used Autopsy this should be pretty simple. Keep the FIRE CD > handy as it's a great tool to use. > > Frank Kenisky IV, CISSP, CISA, CISM > Information Technical Security Specialist > (210) 301-6433 - (210) 887-6985 > > > *"te...@me..." <te...@me...>* > Sent by: sle...@li... > > 01/24/2006 04:56 AM > > > To > sle...@li... > cc > > Subject > [sleuthkit-users] How to simply undelete files ? > > > > > > > > > Hello everybody, > I'm new to sleuthkit,and I've got a problem which might seem very basic > to most og you but I can't resolve it : > I recently burned some files from my hard-disk to a CD / RW, then I > deleted these files from my hard-disk. > When I tried to read the CD, there seems to be nothing on it. > I wasn't able to dd an image of the cd, so I can't recover my files this > way. > Then I launched autopsy on my hard-disk. Using File analysis, I can see > all the deleted files, but now, I don't know how > to recover them. I don't want to use the sorter tool from autopsy > because I don't have enough free space to copy all the > recovered files, only enough for the 700Mb of my deleted files. > I would like to know what is the simple procedure to recover one by one > a few files which seems I good state to recover > (as the partition where I deleted files wasn't mounted since the deletion). > > > ------------------------------------------------------- > This SF.net email is sponsored by: Splunk Inc. Do you grep through log files > for problems? Stop! Download the new AJAX search engine that makes > searching your log files as easy as surfing the web. DOWNLOAD SPLUNK! > http://sel.as-us.falkag.net/sel?cmd=lnk&kid=103432&bid=230486&dat=121642 > _______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org > |
From: <te...@me...> - 2006-01-24 15:44:10
|
Is it possible to get some datas on the CD / RW even if it seems unreadable with dd not working ? |
From: Barry J. G. <bg...@im...> - 2006-01-24 14:43:26
|
On Tue, 2006-01-24 at 11:56 +0100, te...@me... wrote: > I would like to know what is the simple procedure to recover one by one a few files which seems I good state to recover > (as the partition where I deleted files wasn't mounted since the deletion). The ease of this will depend on the filesystem these files are on. For starters, have a look at the man page for icat (with the -r option). use fls to find the inodes of deleted files, then pass the inode as an argument to icat to recover the file. Again, the sucess of this will depend on the FS type. -- /*************************************** Special Agent Barry J. Grundy NASA Office of Inspector General Computer Crimes Division Goddard Space Flight Center Code 190 Greenbelt Rd. Greenbelt, MD 20771 (301)286-3358 **************************************/ |
From: <te...@me...> - 2006-01-24 10:55:02
|
Hello everybody, I'm new to sleuthkit,and I've got a problem which might seem very basic to most og you but I can't resolve it : I recently burned some files from my hard-disk to a CD / RW, then I deleted these files from my hard-disk. When I tried to read the CD, there seems to be nothing on it. I wasn't able to dd an image of the cd, so I can't recover my files this way. Then I launched autopsy on my hard-disk. Using File analysis, I can see all the deleted files, but now, I don't know how to recover them. I don't want to use the sorter tool from autopsy because I don't have enough free space to copy all the recovered files, only enough for the 700Mb of my deleted files. I would like to know what is the simple procedure to recover one by one a few files which seems I good state to recover (as the partition where I deleted files wasn't mounted since the deletion). |
From: Brian C. <ca...@sl...> - 2006-01-23 23:32:56
|
Some additional comments are inline: >> 2) Are EnCase images supported at all? I can import >> EnCase images into a >> case, but none of the operations I attempt seem to >> execute correctly. > > No. Autopsy (TSK in fact) supports raw image format. The EnCase format support should exist soon. >> 3) Can a SHA-1 hash be generated when an image is >> imported. When I import >> an image, I have the option of generating an MD5 >> hash, but I don't see >> SHA-1. > > You can use sha in TSK but it is no incorporated yet > in Autopsy. This is also on the todo list. > >> 6) Is it possible to generate reports at a higher >> granularity than files. >> That is, can a report be generated for a host or a >> case that contains >> information about multiple files? Can notes be >> included in reports? > > Autopsy is still weak in the reporting side. it doesnt > generate a decent report, but it does log all the > investigator actions which could be inlcuded in the > report. I recently received some patches from Regis Cassidy that greatly improves the reporting. That should be incorporated into the next version. brian |