sleuthkit-users Mailing List for The Sleuth Kit (Page 178)
Brought to you by:
carrier
You can subscribe to this list here.
| 2002 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
(6) |
Aug
|
Sep
(11) |
Oct
(5) |
Nov
(4) |
Dec
|
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2003 |
Jan
(1) |
Feb
(20) |
Mar
(60) |
Apr
(40) |
May
(24) |
Jun
(28) |
Jul
(18) |
Aug
(27) |
Sep
(6) |
Oct
(14) |
Nov
(15) |
Dec
(22) |
| 2004 |
Jan
(34) |
Feb
(13) |
Mar
(28) |
Apr
(23) |
May
(27) |
Jun
(26) |
Jul
(37) |
Aug
(19) |
Sep
(20) |
Oct
(39) |
Nov
(17) |
Dec
(9) |
| 2005 |
Jan
(45) |
Feb
(43) |
Mar
(66) |
Apr
(36) |
May
(19) |
Jun
(64) |
Jul
(10) |
Aug
(11) |
Sep
(35) |
Oct
(6) |
Nov
(4) |
Dec
(13) |
| 2006 |
Jan
(52) |
Feb
(34) |
Mar
(39) |
Apr
(39) |
May
(37) |
Jun
(15) |
Jul
(13) |
Aug
(48) |
Sep
(9) |
Oct
(10) |
Nov
(47) |
Dec
(13) |
| 2007 |
Jan
(25) |
Feb
(4) |
Mar
(2) |
Apr
(29) |
May
(11) |
Jun
(19) |
Jul
(13) |
Aug
(15) |
Sep
(30) |
Oct
(12) |
Nov
(10) |
Dec
(13) |
| 2008 |
Jan
(2) |
Feb
(54) |
Mar
(58) |
Apr
(43) |
May
(10) |
Jun
(27) |
Jul
(25) |
Aug
(27) |
Sep
(48) |
Oct
(69) |
Nov
(55) |
Dec
(43) |
| 2009 |
Jan
(26) |
Feb
(36) |
Mar
(28) |
Apr
(27) |
May
(55) |
Jun
(9) |
Jul
(19) |
Aug
(16) |
Sep
(15) |
Oct
(17) |
Nov
(70) |
Dec
(21) |
| 2010 |
Jan
(56) |
Feb
(59) |
Mar
(53) |
Apr
(32) |
May
(25) |
Jun
(31) |
Jul
(36) |
Aug
(11) |
Sep
(37) |
Oct
(19) |
Nov
(23) |
Dec
(6) |
| 2011 |
Jan
(21) |
Feb
(20) |
Mar
(30) |
Apr
(30) |
May
(74) |
Jun
(50) |
Jul
(34) |
Aug
(34) |
Sep
(12) |
Oct
(33) |
Nov
(10) |
Dec
(8) |
| 2012 |
Jan
(23) |
Feb
(57) |
Mar
(26) |
Apr
(14) |
May
(27) |
Jun
(27) |
Jul
(60) |
Aug
(88) |
Sep
(13) |
Oct
(36) |
Nov
(97) |
Dec
(85) |
| 2013 |
Jan
(60) |
Feb
(24) |
Mar
(43) |
Apr
(32) |
May
(22) |
Jun
(38) |
Jul
(51) |
Aug
(50) |
Sep
(76) |
Oct
(65) |
Nov
(25) |
Dec
(30) |
| 2014 |
Jan
(19) |
Feb
(41) |
Mar
(43) |
Apr
(28) |
May
(61) |
Jun
(12) |
Jul
(10) |
Aug
(37) |
Sep
(76) |
Oct
(31) |
Nov
(41) |
Dec
(12) |
| 2015 |
Jan
(33) |
Feb
(28) |
Mar
(53) |
Apr
(22) |
May
(29) |
Jun
(20) |
Jul
(15) |
Aug
(17) |
Sep
(52) |
Oct
(3) |
Nov
(18) |
Dec
(21) |
| 2016 |
Jan
(20) |
Feb
(8) |
Mar
(21) |
Apr
(7) |
May
(13) |
Jun
(35) |
Jul
(34) |
Aug
(11) |
Sep
(14) |
Oct
(22) |
Nov
(31) |
Dec
(23) |
| 2017 |
Jan
(20) |
Feb
(7) |
Mar
(5) |
Apr
(6) |
May
(6) |
Jun
(22) |
Jul
(11) |
Aug
(16) |
Sep
(8) |
Oct
(1) |
Nov
(1) |
Dec
(1) |
| 2018 |
Jan
|
Feb
|
Mar
(16) |
Apr
(2) |
May
(6) |
Jun
(5) |
Jul
|
Aug
(2) |
Sep
(4) |
Oct
|
Nov
(16) |
Dec
(13) |
| 2019 |
Jan
|
Feb
(1) |
Mar
(25) |
Apr
(9) |
May
(2) |
Jun
(1) |
Jul
(1) |
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
| 2020 |
Jan
(2) |
Feb
|
Mar
(1) |
Apr
|
May
(1) |
Jun
(3) |
Jul
(2) |
Aug
|
Sep
|
Oct
(5) |
Nov
|
Dec
|
| 2021 |
Jan
|
Feb
|
Mar
(1) |
Apr
|
May
|
Jun
(4) |
Jul
(1) |
Aug
|
Sep
(1) |
Oct
|
Nov
(1) |
Dec
|
| 2022 |
Jan
|
Feb
(2) |
Mar
|
Apr
|
May
(2) |
Jun
|
Jul
(3) |
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
| 2023 |
Jan
(2) |
Feb
|
Mar
(1) |
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
(1) |
Nov
|
Dec
|
| 2024 |
Jan
|
Feb
(3) |
Mar
|
Apr
(1) |
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
| 2025 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
(1) |
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
|
From: <fu...@gm...> - 2005-06-24 13:12:17
|
Hi Once more, I'm looking at a NTFS-Disk. When I mount ro the disk, I can see in a directory the File archive2005.pst with the following permission: -r-------- 1 0 2005-06-06 08:30 archive2004.pst So file size is 0, the rest seems okay. But when I go to the directory in Autopsy, the file does not appear. What did happen here? Any information I can provide you? I use Autopsy 2.05 and sleuthkit 2.01 on a Debian Sarge. The other issue is: I have a file which looks the following when I do ls -l in the mounted disk: ?--------- 1 0 2002-04-21 11:46 54I70048.jpg When I look into Autops, the file shows not up. If I try to copy the file from the mounted filesystem to somewhere, cp bothers me with "argument is illegal". So there is something wrong with this file but I'm wondering why it's not shown in Autopsy? Thank you for Autopsy and regards Fuerst -- Geschenkt: 3 Monate GMX ProMail gratis + 3 Ausgaben stern gratis ++ Jetzt anmelden & testen ++ http://www.gmx.net/de/go/promail ++ |
|
From: <fu...@gm...> - 2005-06-23 09:35:27
|
Mh, maybe I'm slightly offtopic. I have a Disk with NTFS. If it is in a Windows Box and I try to open certain directories, it says "Disk not formatted". Other Directories do work. Is there any way to resolve this problem, like repairing the Master File Table or something? I'll do now an image and load it into Autopsy, will this improve my hopes to get the original structure? Some files alsogive CRC failures by the way. any hint would be appreciated. Thank you Fuerst -- Geschenkt: 3 Monate GMX ProMail gratis + 3 Ausgaben stern gratis ++ Jetzt anmelden & testen ++ http://www.gmx.net/de/go/promail ++ |
|
From: gints <gin...@me...> - 2005-06-21 07:29:18
|
Hallo, any ideas, why happening this: HDD - ExcelStore 40Gb File system - NTFS (primary, bootable) OS - Windows XP After attaching HDD to IDE or IDE USB adapter (as secondary disk), the Master boot sector comes affected, only these records remains SO 440 - EF DF EF DF SO 510 - 55 AA Is there any other reason excepting viruss? Thanks, Gints Erglis. |
|
From: <ro...@mo...> - 2005-06-17 09:54:04
|
Hello, I got everything working. It had everything to do with extracting the tar.gz file with winzip version 9. When I used tar from cygwin everything worked like a charm. I thought winzip 9 did not have issues with tar.gz anymore (CR/LF). How wrong I was. Thanks for the input though. Regards, RJM. > Send sleuthkit-users mailing list submissions to > sle...@li... > > To subscribe or unsubscribe via the World Wide Web, visit > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > or, via email, send a message with subject or body 'help' to > sle...@li... > > You can reach the person managing the list at > sle...@li... > > When replying, please edit your Subject line so it is more specific > than "Re: Contents of sleuthkit-users digest..." > > > Today's Topics: > > 1. Re: Mounting a dd image under windows (Guido Metzner) > 2. cygwin sleuthkit 2.01 compile error (ro...@mo...) > 3. Re: cygwin sleuthkit 2.01 compile error (Paul Bakker) > 4. Re: cygwin sleuthkit 2.01 compile error (Angus Marshall) > 5. Re: cygwin sleuthkit 2.01 compile error (ro...@mo...) > 6. Re: cygwin sleuthkit 2.01 compile error (ro...@mo...) > 7. Re: cygwin sleuthkit 2.01 compile error (Paul Bakker) > > --__--__-- > > Message: 1 > Date: Thu, 16 Jun 2005 07:27:44 +0200 > From: Guido Metzner <gui...@ya...> > To: sle...@li... > CC: tu...@gm... > Subject: Re: [sleuthkit-users] Mounting a dd image under windows > > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > Thanks Thomas, > > I work often with dd images and so I have mark this thread in > expectation of a good answer and resolving. > > Unforunately is it something difficult to find a answer of the question > from Patrick here, because the most answers here are not reffering to > the topic... ;-) > > So I even more happy as I found today your post. I will try out your > hint immediately. > > Regards > Guido > > PS: Sorry for my bad english, I use "Babylon" ;-) > > > Thomas Springer schrieb: > > >> Try FileDisk (http://www.acc.umu.se/%7Ebosse/) > > > > > > Filedisk works perfect, but only with _partitions_, so you'll have to > extract the partitions of your image (again with dd). > > There are other tools to mount or at least read other linux-filesystems > and images like reiserfs under windows. > > > > - -- > - ----------------------------------------------------- > Guido Metzner > > "Software is like sex, it's better, when it's free." > Linus Torvalds > > > Email: gui...@ya... > ICQ : 113662639 > URL : http://www.guframe.de > - ----------------------------------------------------- > -----BEGIN PGP SIGNATURE----- > Version: GnuPG v1.4.0 (MingW32) > Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org > > iD8DBQFCsQ3OwFCOldQoJ1sRAns5AJ95fnqe6CgJ8eJab5AvGBypclPwSwCcC/ut > pzJS/QcYxnNADg/8ek05PtA= > =MuQF > -----END PGP SIGNATURE----- > > > > > > > > ___________________________________________________________ > Gesendet von Yahoo! Mail - Jetzt mit 1GB Speicher kostenlos - Hier anmelden: http://mail.yahoo.de > > > > --__--__-- > > Message: 2 > To: sle...@li... > Cc: sle...@li...; > From: ro...@mo... > Date: Thu, 16 Jun 2005 08:16:33 GMT > Subject: [sleuthkit-users] cygwin sleuthkit 2.01 compile error > > Hello, > > I want to install the latest version of the sleuthkit under cygwin on windows XP. Paul > told me to install the latest cygwin. I've done that but keep getting the same compile > errors in windows XP dutch and english versions. I've installed the latest cygwin+ > sleuthkit on a windows 2000 client. Everything works fine, but I want the latest version > to work under cygwin with windows XP. > > I'm keep getting the same following error messages on different machines with XP > installed; > > magic type offset invalid(numerous times) messages. > > file: could not find any magic files! > make[2]:***[magic.mgc] error 255 > make[2]: leaving directory "/usr/local/sleuthkit2-.01/src/file/magic" > make[1]: ***[install recursive]error 1 > make [1]: leaving directory "/usr/local/sleuthkit2-.01/src/file" > make:***[file] error 2 > > > I'm getting a little bit frustrated about it and hope that someone has the solution. > > RJM. > > > > > > --__--__-- > > Message: 3 > Date: Thu, 16 Jun 2005 10:35:25 +0200 > From: Paul Bakker <p.j...@br...> > To: ro...@mo... > Cc: sle...@li..., > sle...@li...; > Subject: Re: [sleuthkit-users] cygwin sleuthkit 2.01 compile error > > Hmm.. > > Then I do have to inform you that I did all that (My testing) on a > Windows XP machine!.. So that is not the case... I think it is more > something of environment variables/tools missing or too much on your XP > machine. > > I would like to help, but without being able to reproduce the problem, > that is hard. > > Are you sure you installed the same tools within cygwin at both PC's? > > Paul > > On Thu, Jun 16, 2005 at 08:16:33AM +0000, ro...@mo... wrote: > > Hello, > > > > I want to install the latest version of the sleuthkit under cygwin on windows XP. Paul > > told me to install the latest cygwin. I've done that but keep getting the same compile > > errors in windows XP dutch and english versions. I've installed the latest cygwin+ > > sleuthkit on a windows 2000 client. Everything works fine, but I want the latest version > > to work under cygwin with windows XP. > > > > I'm keep getting the same following error messages on different machines with XP > > installed; > > > > magic type offset invalid(numerous times) messages. > > > > file: could not find any magic files! > > make[2]:***[magic.mgc] error 255 > > make[2]: leaving directory "/usr/local/sleuthkit2-.01/src/file/magic" > > make[1]: ***[install recursive]error 1 > > make [1]: leaving directory "/usr/local/sleuthkit2-.01/src/file" > > make:***[file] error 2 > > > > > > I'm getting a little bit frustrated about it and hope that someone has the solution. > > > > RJM. > > > > > > > > > > > > ------------------------------------------------------- > > SF.Net email is sponsored by: Discover Easy Linux Migration Strategies > > from IBM. Find simple to follow Roadmaps, straightforward articles, > > informative Webcasts and more! Get everything you need to get up to > > speed, fast. http://ads.osdn.com/?ad_id=7477&alloc_id=16492&op=click > > _______________________________________________ > > sleuthkit-users mailing list > > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > > http://www.sleuthkit.org > > > --__--__-- > > Message: 4 > From: Angus Marshall <an...@n-...> > To: sle...@li..., > sle...@li... > Subject: Re: [sleuthkit-users] cygwin sleuthkit 2.01 compile error > Reply-To: an...@n-... > Date: Thu, 16 Jun 2005 11:06:22 +0100 > > On Thu Jun 16 9:35 , Paul Bakker <p.j...@br...> sent: > > <snip> > > >Are you sure you installed the same tools within cygwin at both PC's? > > > >Paul > > > >On Thu, Jun 16, 2005 at 08:16:33AM +0000, ro...@mo... wrote: > >> Hello, > >> > <snip> > > >> I'm keep getting the same following error messages on different machines with XP > >> installed; > >> > >> magic type offset invalid(numerous times) messages. > >> > >> file: could not find any magic files! > >> make[2]:***[magic.mgc] error 255 > >> make[2]: leaving directory "/usr/local/sleuthkit2-.01/src/file/magic" > >> make[1]: ***[install recursive]error 1 > >> make [1]: leaving directory "/usr/local/sleuthkit2-.01/src/file" > >> make:***[file] error 2 > > > According to a quick GOOGLE (GIYF) - magic.mgc is part of the "file" package for > cygwin - are you sure you have installed this ? The magic.mgc file itself should > be in /usr/share/file > > See also : http://www.cygwin.com/packages/file/ > > If this is not the cause - we need the FIRST error lines from make because they > will contain the real error, the set posted here just tell us that make is > abandoning because of earlier errors. > > > --__--__-- > > Message: 5 > To: Paul Bakker <p.j...@br...>, ro...@mo..., sle...@li...,sle...@li..., > From: ro...@mo... > Subject: Re: [sleuthkit-users] cygwin sleuthkit 2.01 compile error > Date: Thu, 16 Jun 2005 11:37:47 GMT > > Hmmmmm...... Paul, I've installed everything from the latest cygwin on 3 windows XP > machines. I've added the magic location in an environement variable no luck so far. > > This morning I've tried to install 2.00, same error messages on XP. > > Did you install everything from cygwin or the default? > > RJM. > > > > Hmm.. > > > > Then I do have to inform you that I did all that (My testing) on a > > Windows XP machine!.. So that is not the case... I think it is more > > something of environment variables/tools missing or too much on your XP > > machine. > > > > I would like to help, but without being able to reproduce the problem, > > that is hard. > > > > Are you sure you installed the same tools within cygwin at both PC's? > > > > Paul > > > > On Thu, Jun 16, 2005 at 08:16:33AM +0000, ro...@mo... wrote: > > > Hello, > > > > > > I want to install the latest version of the sleuthkit under cygwin on windows XP. Paul > > > told me to install the latest cygwin. I've done that but keep getting the same compile > > > errors in windows XP dutch and english versions. I've installed the latest cygwin+ > > > sleuthkit on a windows 2000 client. Everything works fine, but I want the latest > version > > > > to work under cygwin with windows XP. > > > > > > I'm keep getting the same following error messages on different machines with XP > > > installed; > > > > > > magic type offset invalid(numerous times) messages. > > > > > > file: could not find any magic files! > > > make[2]:***[magic.mgc] error 255 > > > make[2]: leaving directory "/usr/local/sleuthkit2-.01/src/file/magic" > > > make[1]: ***[install recursive]error 1 > > > make [1]: leaving directory "/usr/local/sleuthkit2-.01/src/file" > > > make:***[file] error 2 > > > > > > > > > I'm getting a little bit frustrated about it and hope that someone has the solution. > > > > > > RJM. > > > > > > > > > > > > > > > > > > ------------------------------------------------------- > > > SF.Net email is sponsored by: Discover Easy Linux Migration Strategies > > > from IBM. Find simple to follow Roadmaps, straightforward articles, > > > informative Webcasts and more! Get everything you need to get up to > > > speed, fast. http://ads.osdn.com/?ad_id=7477&alloc_id=16492&op=click > > > _______________________________________________ > > > sleuthkit-users mailing list > > > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > > > http://www.sleuthkit.org > > > > > --__--__-- > > Message: 6 > To: Paul Bakker <p.j...@br...>, ro...@mo..., sle...@li...,sle...@li..., > From: ro...@mo... > Subject: Re: [sleuthkit-users] cygwin sleuthkit 2.01 compile error > Date: Thu, 16 Jun 2005 11:37:33 GMT > > Hmmmmm...... Paul, I've installed everything from the latest cygwin on 3 windows XP > machines. I've added the magic location in an environement variable no luck so far. > > This morning I've tried to install 2.00, same error messages on XP. > > Did you install everything from cygwin or the default? > > RJM. > > > > Hmm.. > > > > Then I do have to inform you that I did all that (My testing) on a > > Windows XP machine!.. So that is not the case... I think it is more > > something of environment variables/tools missing or too much on your XP > > machine. > > > > I would like to help, but without being able to reproduce the problem, > > that is hard. > > > > Are you sure you installed the same tools within cygwin at both PC's? > > > > Paul > > > > On Thu, Jun 16, 2005 at 08:16:33AM +0000, ro...@mo... wrote: > > > Hello, > > > > > > I want to install the latest version of the sleuthkit under cygwin on windows XP. Paul > > > told me to install the latest cygwin. I've done that but keep getting the same compile > > > errors in windows XP dutch and english versions. I've installed the latest cygwin+ > > > sleuthkit on a windows 2000 client. Everything works fine, but I want the latest > version > > > > to work under cygwin with windows XP. > > > > > > I'm keep getting the same following error messages on different machines with XP > > > installed; > > > > > > magic type offset invalid(numerous times) messages. > > > > > > file: could not find any magic files! > > > make[2]:***[magic.mgc] error 255 > > > make[2]: leaving directory "/usr/local/sleuthkit2-.01/src/file/magic" > > > make[1]: ***[install recursive]error 1 > > > make [1]: leaving directory "/usr/local/sleuthkit2-.01/src/file" > > > make:***[file] error 2 > > > > > > > > > I'm getting a little bit frustrated about it and hope that someone has the solution. > > > > > > RJM. > > > > > > > > > > > > > > > > > > ------------------------------------------------------- > > > SF.Net email is sponsored by: Discover Easy Linux Migration Strategies > > > from IBM. Find simple to follow Roadmaps, straightforward articles, > > > informative Webcasts and more! Get everything you need to get up to > > > speed, fast. http://ads.osdn.com/?ad_id=7477&alloc_id=16492&op=click > > > _______________________________________________ > > > sleuthkit-users mailing list > > > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > > > http://www.sleuthkit.org > > > > > --__--__-- > > Message: 7 > Date: Thu, 16 Jun 2005 14:02:12 +0200 > From: Paul Bakker <p.j...@br...> > To: ro...@mo... > Cc: sle...@li..., > sle...@li... > Subject: Re: [sleuthkit-users] cygwin sleuthkit 2.01 compile error > > No.. I just installed the default with some basic packages for > compilation.. I don't know the complete list out of the top of my head. > > Paul > > On Thu, Jun 16, 2005 at 11:37:47AM +0000, ro...@mo... wrote: > > Hmmmmm...... Paul, I've installed everything from the latest cygwin on 3 windows XP > > machines. I've added the magic location in an environement variable no luck so far. > > > > This morning I've tried to install 2.00, same error messages on XP. > > > > Did you install everything from cygwin or the default? > > > > RJM. > > > > > > > Hmm.. > > > > > > Then I do have to inform you that I did all that (My testing) on a > > > Windows XP machine!.. So that is not the case... I think it is more > > > something of environment variables/tools missing or too much on your XP > > > machine. > > > > > > I would like to help, but without being able to reproduce the problem, > > > that is hard. > > > > > > Are you sure you installed the same tools within cygwin at both PC's? > > > > > > Paul > > > > > > On Thu, Jun 16, 2005 at 08:16:33AM +0000, ro...@mo... wrote: > > > > Hello, > > > > > > > > I want to install the latest version of the sleuthkit under cygwin on windows XP. Paul > > > > told me to install the latest cygwin. I've done that but keep getting the same compile > > > > errors in windows XP dutch and english versions. I've installed the latest cygwin+ > > > > sleuthkit on a windows 2000 client. Everything works fine, but I want the latest > > version > > > > > > to work under cygwin with windows XP. > > > > > > > > I'm keep getting the same following error messages on different machines with XP > > > > installed; > > > > > > > > magic type offset invalid(numerous times) messages. > > > > > > > > file: could not find any magic files! > > > > make[2]:***[magic.mgc] error 255 > > > > make[2]: leaving directory "/usr/local/sleuthkit2-.01/src/file/magic" > > > > make[1]: ***[install recursive]error 1 > > > > make [1]: leaving directory "/usr/local/sleuthkit2-.01/src/file" > > > > make:***[file] error 2 > > > > > > > > > > > > I'm getting a little bit frustrated about it and hope that someone has the solution. > > > > > > > > RJM. > > > > > > > > > > > > > > > > > > > > > > > > ------------------------------------------------------- > > > > SF.Net email is sponsored by: Discover Easy Linux Migration Strategies > > > > from IBM. Find simple to follow Roadmaps, straightforward articles, > > > > informative Webcasts and more! Get everything you need to get up to > > > > speed, fast. http://ads.osdn.com/?ad_id=7477&alloc_id=16492&op=click > > > > _______________________________________________ > > > > sleuthkit-users mailing list > > > > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > > > > http://www.sleuthkit.org > > > > > > > > > > ------------------------------------------------------- > > SF.Net email is sponsored by: Discover Easy Linux Migration Strategies > > from IBM. Find simple to follow Roadmaps, straightforward articles, > > informative Webcasts and more! Get everything you need to get up to > > speed, fast. http://ads.osdn.com/?ad_id=7477&alloc_id=16492&op=click > > _______________________________________________ > > sleuthkit-users mailing list > > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > > http://www.sleuthkit.org > > > > --__--__-- > > _______________________________________________ > sleuthkit-users mailing list > sle...@li... > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > > > End of sleuthkit-users Digest |
|
From: <fu...@gm...> - 2005-06-17 08:34:00
|
Hi everybody I compiled some command-line commands for sleuthkit for myself, maybe it is usefull for someone else. Furthermore I did some time testings, how much time a step needs to proceed, hopefully this list will grow: http://mocken.kicks-ass.org/sleuthkit.html Hints, tips and so are welcome regard and thanks everybody Fuerst -- Weitersagen: GMX DSL-Flatrates mit Tempo-Garantie! Ab 4,99 Euro/Monat: http://www.gmx.net/de/go/dsl |
|
From: Paul B. <p.j...@br...> - 2005-06-16 12:03:35
|
No.. I just installed the default with some basic packages for compilation.. I don't know the complete list out of the top of my head. Paul On Thu, Jun 16, 2005 at 11:37:47AM +0000, ro...@mo... wrote: > Hmmmmm...... Paul, I've installed everything from the latest cygwin on 3 windows XP > machines. I've added the magic location in an environement variable no luck so far. > > This morning I've tried to install 2.00, same error messages on XP. > > Did you install everything from cygwin or the default? > > RJM. > > > > Hmm.. > > > > Then I do have to inform you that I did all that (My testing) on a > > Windows XP machine!.. So that is not the case... I think it is more > > something of environment variables/tools missing or too much on your XP > > machine. > > > > I would like to help, but without being able to reproduce the problem, > > that is hard. > > > > Are you sure you installed the same tools within cygwin at both PC's? > > > > Paul > > > > On Thu, Jun 16, 2005 at 08:16:33AM +0000, ro...@mo... wrote: > > > Hello, > > > > > > I want to install the latest version of the sleuthkit under cygwin on windows XP. Paul > > > told me to install the latest cygwin. I've done that but keep getting the same compile > > > errors in windows XP dutch and english versions. I've installed the latest cygwin+ > > > sleuthkit on a windows 2000 client. Everything works fine, but I want the latest > version > > > > to work under cygwin with windows XP. > > > > > > I'm keep getting the same following error messages on different machines with XP > > > installed; > > > > > > magic type offset invalid(numerous times) messages. > > > > > > file: could not find any magic files! > > > make[2]:***[magic.mgc] error 255 > > > make[2]: leaving directory "/usr/local/sleuthkit2-.01/src/file/magic" > > > make[1]: ***[install recursive]error 1 > > > make [1]: leaving directory "/usr/local/sleuthkit2-.01/src/file" > > > make:***[file] error 2 > > > > > > > > > I'm getting a little bit frustrated about it and hope that someone has the solution. > > > > > > RJM. > > > > > > > > > > > > > > > > > > ------------------------------------------------------- > > > SF.Net email is sponsored by: Discover Easy Linux Migration Strategies > > > from IBM. Find simple to follow Roadmaps, straightforward articles, > > > informative Webcasts and more! Get everything you need to get up to > > > speed, fast. http://ads.osdn.com/?ad_id=7477&alloc_id=16492&op=click > > > _______________________________________________ > > > sleuthkit-users mailing list > > > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > > > http://www.sleuthkit.org > > > > > ------------------------------------------------------- > SF.Net email is sponsored by: Discover Easy Linux Migration Strategies > from IBM. Find simple to follow Roadmaps, straightforward articles, > informative Webcasts and more! Get everything you need to get up to > speed, fast. http://ads.osdn.com/?ad_id=7477&alloc_id=16492&op=click > _______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org |
|
From: <ro...@mo...> - 2005-06-16 11:38:20
|
Hmmmmm...... Paul, I've installed everything from the latest cygwin on 3 windows XP machines. I've added the magic location in an environement variable no luck so far. This morning I've tried to install 2.00, same error messages on XP. Did you install everything from cygwin or the default? RJM. > Hmm.. > > Then I do have to inform you that I did all that (My testing) on a > Windows XP machine!.. So that is not the case... I think it is more > something of environment variables/tools missing or too much on your XP > machine. > > I would like to help, but without being able to reproduce the problem, > that is hard. > > Are you sure you installed the same tools within cygwin at both PC's? > > Paul > > On Thu, Jun 16, 2005 at 08:16:33AM +0000, ro...@mo... wrote: > > Hello, > > > > I want to install the latest version of the sleuthkit under cygwin on windows XP. Paul > > told me to install the latest cygwin. I've done that but keep getting the same compile > > errors in windows XP dutch and english versions. I've installed the latest cygwin+ > > sleuthkit on a windows 2000 client. Everything works fine, but I want the latest version > > to work under cygwin with windows XP. > > > > I'm keep getting the same following error messages on different machines with XP > > installed; > > > > magic type offset invalid(numerous times) messages. > > > > file: could not find any magic files! > > make[2]:***[magic.mgc] error 255 > > make[2]: leaving directory "/usr/local/sleuthkit2-.01/src/file/magic" > > make[1]: ***[install recursive]error 1 > > make [1]: leaving directory "/usr/local/sleuthkit2-.01/src/file" > > make:***[file] error 2 > > > > > > I'm getting a little bit frustrated about it and hope that someone has the solution. > > > > RJM. > > > > > > > > > > > > ------------------------------------------------------- > > SF.Net email is sponsored by: Discover Easy Linux Migration Strategies > > from IBM. Find simple to follow Roadmaps, straightforward articles, > > informative Webcasts and more! Get everything you need to get up to > > speed, fast. http://ads.osdn.com/?ad_id=7477&alloc_id=16492&op=click > > _______________________________________________ > > sleuthkit-users mailing list > > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > > http://www.sleuthkit.org |
|
From: <ro...@mo...> - 2005-06-16 11:37:54
|
Hmmmmm...... Paul, I've installed everything from the latest cygwin on 3 windows XP machines. I've added the magic location in an environement variable no luck so far. This morning I've tried to install 2.00, same error messages on XP. Did you install everything from cygwin or the default? RJM. > Hmm.. > > Then I do have to inform you that I did all that (My testing) on a > Windows XP machine!.. So that is not the case... I think it is more > something of environment variables/tools missing or too much on your XP > machine. > > I would like to help, but without being able to reproduce the problem, > that is hard. > > Are you sure you installed the same tools within cygwin at both PC's? > > Paul > > On Thu, Jun 16, 2005 at 08:16:33AM +0000, ro...@mo... wrote: > > Hello, > > > > I want to install the latest version of the sleuthkit under cygwin on windows XP. Paul > > told me to install the latest cygwin. I've done that but keep getting the same compile > > errors in windows XP dutch and english versions. I've installed the latest cygwin+ > > sleuthkit on a windows 2000 client. Everything works fine, but I want the latest version > > to work under cygwin with windows XP. > > > > I'm keep getting the same following error messages on different machines with XP > > installed; > > > > magic type offset invalid(numerous times) messages. > > > > file: could not find any magic files! > > make[2]:***[magic.mgc] error 255 > > make[2]: leaving directory "/usr/local/sleuthkit2-.01/src/file/magic" > > make[1]: ***[install recursive]error 1 > > make [1]: leaving directory "/usr/local/sleuthkit2-.01/src/file" > > make:***[file] error 2 > > > > > > I'm getting a little bit frustrated about it and hope that someone has the solution. > > > > RJM. > > > > > > > > > > > > ------------------------------------------------------- > > SF.Net email is sponsored by: Discover Easy Linux Migration Strategies > > from IBM. Find simple to follow Roadmaps, straightforward articles, > > informative Webcasts and more! Get everything you need to get up to > > speed, fast. http://ads.osdn.com/?ad_id=7477&alloc_id=16492&op=click > > _______________________________________________ > > sleuthkit-users mailing list > > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > > http://www.sleuthkit.org |
|
From: Angus M. <an...@n-...> - 2005-06-16 09:50:48
|
On Thu Jun 16 9:35 , Paul Bakker <p.j...@br...> sent: <snip> >Are you sure you installed the same tools within cygwin at both PC's? > >Paul > >On Thu, Jun 16, 2005 at 08:16:33AM +0000, ro...@mo... wrote: >> Hello, >> <snip> >> I'm keep getting the same following error messages on different machines with XP >> installed; >> >> magic type offset invalid(numerous times) messages. >> >> file: could not find any magic files! >> make[2]:***[magic.mgc] error 255 >> make[2]: leaving directory "/usr/local/sleuthkit2-.01/src/file/magic" >> make[1]: ***[install recursive]error 1 >> make [1]: leaving directory "/usr/local/sleuthkit2-.01/src/file" >> make:***[file] error 2 According to a quick GOOGLE (GIYF) - magic.mgc is part of the "file" package for cygwin - are you sure you have installed this ? The magic.mgc file itself should be in /usr/share/file See also : http://www.cygwin.com/packages/file/ If this is not the cause - we need the FIRST error lines from make because they will contain the real error, the set posted here just tell us that make is abandoning because of earlier errors. |
|
From: Paul B. <p.j...@br...> - 2005-06-16 08:36:39
|
Hmm.. Then I do have to inform you that I did all that (My testing) on a Windows XP machine!.. So that is not the case... I think it is more something of environment variables/tools missing or too much on your XP machine. I would like to help, but without being able to reproduce the problem, that is hard. Are you sure you installed the same tools within cygwin at both PC's? Paul On Thu, Jun 16, 2005 at 08:16:33AM +0000, ro...@mo... wrote: > Hello, > > I want to install the latest version of the sleuthkit under cygwin on windows XP. Paul > told me to install the latest cygwin. I've done that but keep getting the same compile > errors in windows XP dutch and english versions. I've installed the latest cygwin+ > sleuthkit on a windows 2000 client. Everything works fine, but I want the latest version > to work under cygwin with windows XP. > > I'm keep getting the same following error messages on different machines with XP > installed; > > magic type offset invalid(numerous times) messages. > > file: could not find any magic files! > make[2]:***[magic.mgc] error 255 > make[2]: leaving directory "/usr/local/sleuthkit2-.01/src/file/magic" > make[1]: ***[install recursive]error 1 > make [1]: leaving directory "/usr/local/sleuthkit2-.01/src/file" > make:***[file] error 2 > > > I'm getting a little bit frustrated about it and hope that someone has the solution. > > RJM. > > > > > > ------------------------------------------------------- > SF.Net email is sponsored by: Discover Easy Linux Migration Strategies > from IBM. Find simple to follow Roadmaps, straightforward articles, > informative Webcasts and more! Get everything you need to get up to > speed, fast. http://ads.osdn.com/?ad_id=7477&alloc_id=16492&op=click > _______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org |
|
From: <ro...@mo...> - 2005-06-16 08:16:55
|
Hello, I want to install the latest version of the sleuthkit under cygwin on windows XP. Paul told me to install the latest cygwin. I've done that but keep getting the same compile errors in windows XP dutch and english versions. I've installed the latest cygwin+ sleuthkit on a windows 2000 client. Everything works fine, but I want the latest version to work under cygwin with windows XP. I'm keep getting the same following error messages on different machines with XP installed; magic type offset invalid(numerous times) messages. file: could not find any magic files! make[2]:***[magic.mgc] error 255 make[2]: leaving directory "/usr/local/sleuthkit2-.01/src/file/magic" make[1]: ***[install recursive]error 1 make [1]: leaving directory "/usr/local/sleuthkit2-.01/src/file" make:***[file] error 2 I'm getting a little bit frustrated about it and hope that someone has the solution. RJM. |
|
From: Guido M. <gui...@ya...> - 2005-06-16 05:27:20
|
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Thanks Thomas, I work often with dd images and so I have mark this thread in expectation of a good answer and resolving. Unforunately is it something difficult to find a answer of the question from Patrick here, because the most answers here are not reffering to the topic... ;-) So I even more happy as I found today your post. I will try out your hint immediately. Regards Guido PS: Sorry for my bad english, I use "Babylon" ;-) Thomas Springer schrieb: >> Try FileDisk (http://www.acc.umu.se/%7Ebosse/) > > > Filedisk works perfect, but only with _partitions_, so you'll have to extract the partitions of your image (again with dd). > There are other tools to mount or at least read other linux-filesystems and images like reiserfs under windows. > - -- - ----------------------------------------------------- Guido Metzner "Software is like sex, it's better, when it's free." Linus Torvalds Email: gui...@ya... ICQ : 113662639 URL : http://www.guframe.de - ----------------------------------------------------- -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.0 (MingW32) Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org iD8DBQFCsQ3OwFCOldQoJ1sRAns5AJ95fnqe6CgJ8eJab5AvGBypclPwSwCcC/ut pzJS/QcYxnNADg/8ek05PtA= =MuQF -----END PGP SIGNATURE----- ___________________________________________________________ Gesendet von Yahoo! Mail - Jetzt mit 1GB Speicher kostenlos - Hier anmelden: http://mail.yahoo.de |
|
From: Altheide, C. B. (IARC) <Alt...@nv...> - 2005-06-15 23:03:54
|
> -----Original Message----- > From: youcef bichbiche [mailto:ybi...@ya...] > Sent: Wednesday, June 15, 2005 3:46 PM > To: Altheide, Cory B. (IARC); 'ro...@mo...'; > sle...@li... > Subject: RE: [sleuthkit-users] Mounting a dd image under windows > > There is always a limit of how you express your > frustration. You don't know me very well. ;) > Surely accusing my contribution, which was purely > meant to be a help and a pointer, A pointer in the *wrong direction* isn't helpful, no matter the intentions. If someone stops you on the street and says "Do you know the way to XYZ street?" do you say "oh, I've been to a 123 street before, I'll tell him how to get there!" or do you respond "Sorry, I don't know"? ... > Now to clarify my posting: > > I used mounted images under Linux, that's why I > thought the fact I can use it under Linux you can do > so under Cygwin. I didn't try it under cygwin, and > that was my mistake, I shouldn't assume it will work. Moreover, one should never state untested assertion as fact. That'd be fine if this was the "making stuff up" list, but it's not - it's a list for users of *forensic utilities*. Far too often the "forensic community" fails to perform the most basic tasks required of it. 1) Test 2) Verify 3) Assert You don't have to be right - just don't be *wrong*. > I cannot deny something I've done, have seen, and have > touched. To inquire how it's possible to do it, the > person in charge "not my friend in the local pub" told > me this: > > - Use the enhanced loopback driver developed by NASA > Computer Crimes Division: > ftp://ftp.hq.nasa.gov/pub/ig/ccd/enhanced_loopback/ "linux-2.4.28-enhanced_loop.tar.gz" The enhanced *LINUX* loopback driver. Which works great. In Linux. Which Cygwin is not. -- Cory |
|
From: youcef b. <ybi...@ya...> - 2005-06-15 22:46:37
|
Mr Altheide, There is always a limit of how you express your frustration. Surely accusing my contribution, which was purely meant to be a help and a pointer, as blatant, misleading, etc, is something that I DONT ACCEPT. You have all right to reject it, but dont get personal. Also, reading you latest comment I felt like I am listening to Donald Ramsfield IRAQs motto Show and awe !!!? please dont over exaggerate. Now to clarify my posting: I used mounted images under Linux, thats why I thought the fact I can use it under Linux you can do so under Cygwin. I didnt try it under cygwin, and that was my mistake, I shouldnt assume it will work. As for what you believe, I can only tell you this (hoping you accept this kindly without firing on me): I cannot deny something Ive done, have seen, and have touched. To inquire how its possible to do it, the person in charge not my friend in the local pub told me this: - Use the enhanced loopback driver developed by NASA Computer Crimes Division: ftp://ftp.hq.nasa.gov/pub/ig/ccd/enhanced_loopback/ - In case you dont want to screw up the kernel follow this guide: http://www.crazytrain.com/monkeyboy/FSK.pdf This is not first-hand information, but I trust the source. Again, the intention is to help you not to mislead, misinform, shock, awe, etc. Regards Youcef --- "Altheide, Cory B. (IARC)" <Alt...@nv...> wrote: > > -----Original Message----- > > From: ro...@mo... [mailto:ro...@mo...] > > > Sent: Wednesday, June 15, 2005 1:09 AM > > To: Bob Older; Altheide, Cory B. (IARC); 'youcef > bichbiche'; > > sle...@li...; > ro...@mo... > > Subject: Re: [sleuthkit-users] Mounting a dd image > under windows > > > > Hello, > > > > Wow, maybe there was a language problem on my > side. Sorry for > > that. > > It happens. ;) > > > Here's the full version. I use cygwin to load dd > images > > into the sleutkit to make timelines etc. and use > > mountimagepro to virtually mount dd images for > virusscanning > > etc. > > The "MountImage Pro" part is a pretty important > ingredient given the > original poster's recipe. :) > > > I believe that paragon mount everything is also > capable > > of doing so. Mounting dd images in cygwin like > mountimage or > > in linux cannot be done to my knowledge. > > That's my understanding as well, hence my original > shock and awe at the > possibility that it could be. > > Cory Altheide > Senior Network Forensics Specialist > NNSA Information Assurance Response Center (IARC) > alt...@nv... > "I have taken all knowledge to be my province." -- > Francis Bacon > > > > > ------------------------------------------------------- > SF.Net email is sponsored by: Discover Easy Linux > Migration Strategies > from IBM. Find simple to follow Roadmaps, > straightforward articles, > informative Webcasts and more! Get everything you > need to get up to > speed, fast. > http://ads.osdn.com/?ad_id=7477&alloc_id=16492&op=click > _______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org > ___________________________________________________________ Yahoo! Messenger - NEW crystal clear PC to PC calling worldwide with voicemail http://uk.messenger.yahoo.com |
|
From: Altheide, C. B. (IARC) <Alt...@nv...> - 2005-06-15 16:48:51
|
> -----Original Message----- > From: ro...@mo... [mailto:ro...@mo...] > Sent: Wednesday, June 15, 2005 1:09 AM > To: Bob Older; Altheide, Cory B. (IARC); 'youcef bichbiche'; > sle...@li...; ro...@mo... > Subject: Re: [sleuthkit-users] Mounting a dd image under windows > > Hello, > > Wow, maybe there was a language problem on my side. Sorry for > that. It happens. ;) > Here's the full version. I use cygwin to load dd images > into the sleutkit to make timelines etc. and use > mountimagepro to virtually mount dd images for virusscanning > etc. The "MountImage Pro" part is a pretty important ingredient given the original poster's recipe. :) > I believe that paragon mount everything is also capable > of doing so. Mounting dd images in cygwin like mountimage or > in linux cannot be done to my knowledge. That's my understanding as well, hence my original shock and awe at the possibility that it could be. Cory Altheide Senior Network Forensics Specialist NNSA Information Assurance Response Center (IARC) alt...@nv... "I have taken all knowledge to be my province." -- Francis Bacon |
|
From: Altheide, C. B. (IARC) <Alt...@nv...> - 2005-06-15 16:46:56
|
> -----Original Message----- > From: Bob Older [mailto:ro...@ec...] > Sent: Tuesday, June 14, 2005 8:07 PM > To: Altheide, Cory B. (IARC) > Cc: 'youcef bichbiche'; > sle...@li...; ro...@mo... > Subject: Re: [sleuthkit-users] Mounting a dd image under windows > > This is to post my objection to the tone and intent of this > email, which I do not believe follows the spirit or intent of > information exchange on sourceforge. The correction of a > fellow posters mistake could be done in an academic format by > presenting the contrary supporting information. It does not > require an accusatory reprimand such as this email contains > and which I find offensive. If a mistake were present, I would have been happy to correct it an an "academic format." An opportunity was given (in the mail I sent previous to this) for the poster to correct any "mistakes" or "mistatements." Said poster then used this opportunity to continue to spread misinformation. I have no tolerance for blatant falsehoods. To summarize: Don't assert BS as fact and expect a gentle correction. Cory Altheide Senior Network Forensics Specialist NNSA Information Assurance Response Center (IARC) alt...@nv... "I have taken all knowledge to be my province." -- Francis Bacon |
|
From: Thomas S. <tu...@gm...> - 2005-06-15 13:56:31
|
> Try FileDisk (http://www.acc.umu.se/%7Ebosse/) Filedisk works perfect, but only with _partitions_, so you'll have to extract the partitions of your image (again with dd). There are other tools to mount or at least read other linux-filesystems and images like reiserfs under windows. -- Grüße, Thomas Springer IT-Security TÜV Informatik und Consulting Services Unternehmensgruppe TÜV Süddeutschland Westendstrasse 199 80686 München Tel: 089/5791-2069 Fax: 089/5791-1355 E-Mail: tho...@tu... ---- The only thing worse than criminally bad perl is reinventing the wheel. |
|
From: Matthew G. <mg...@co...> - 2005-06-15 12:14:24
|
Hi Bob, Bob Older wrote: >This is to post my objection to the tone and intent of this email, which >I do not believe follows the spirit or intent of information exchange on >sourceforge. I think the spirit and intent of this list is to exchange accurate technical information in a field where accuracy is paramount. Bad information -- and by that I mean misleading, untested or speculative information that isn't clearly flagged as such -- is worse than no information. If I post based on something my friend's cousin heard in a bar once, I have an obligation to differentiate it from first-hand knowledge. Cory's responses provided alternative advice for the original poster and corrected bad information. I'm surprised you found anything about his actions offensive. Regards, Matthew Geiger |
|
From: <ro...@mo...> - 2005-06-15 08:09:31
|
Hello, Wow, maybe there was a language problem on my side. Sorry for that. Here's the full version. I use cygwin to load dd images into the sleutkit to make timelines etc. and use mountimagepro to virtually mount dd images for virusscanning etc. I believe that paragon mount everything is also capable of doing so. Mounting dd images in cygwin like mountimage or in linux cannot be done to my knowledge. Hope this helps. > This is to post my objection to the tone and intent of this email, which > I do not believe follows the spirit or intent of information exchange on > sourceforge. The correction of a fellow posters mistake could be done > in an academic format by presenting the contrary supporting information. > It does not require an accusatory reprimand such as this email contains > and which I find offensive. > > Altheide, Cory B. (IARC) wrote: > > -snip- > > Not in Cygwin it doesn't. > > > -snip- > > > > Previously I specifically asked you to explain "how you are currently > > mounting raw disk images unders Windows using Cygwin." > > > > This answer confirms my suspicions that you are currently not doing this /at > > all/. > > -snip- > > > So, I ask again, how you are currently mounting raw disk images unders > Windows using Cygwin? |
|
From: Bob O. <ro...@ec...> - 2005-06-15 03:07:27
|
This is to post my objection to the tone and intent of this email, which I do not believe follows the spirit or intent of information exchange on sourceforge. The correction of a fellow posters mistake could be done in an academic format by presenting the contrary supporting information. It does not require an accusatory reprimand such as this email contains and which I find offensive. Altheide, Cory B. (IARC) wrote: -snip- > Not in Cygwin it doesn't. > -snip- > > Previously I specifically asked you to explain "how you are currently > mounting raw disk images unders Windows using Cygwin." > > This answer confirms my suspicions that you are currently not doing this /at > all/. -snip- > So, I ask again, how you are currently mounting raw disk images unders Windows using Cygwin? |
|
From: Altheide, C. B. (IARC) <Alt...@nv...> - 2005-06-14 00:21:59
|
> -----Original Message-----
> From: youcef bichbiche [mailto:ybi...@ya...]
> Sent: Monday, June 13, 2005 4:49 PM
> To: Altheide, Cory B. (IARC); sle...@li...
> Cc: 'ro...@mo...'
> Subject: RE: [sleuthkit-users] Mounting a dd image under windows
>
>
> Hi,
> It uses the concept of a loopback device, which allows
> to mount a file system within an image file.
Not in Cygwin it doesn't.
> to do that you use the mount command with the loop
> option to indicate that you want to use the loop
> device to mount the file system within the image, and
> you specifiy a disk image rather than a disk device.
>
> Example:
>
> mount -t vfat -o ro,noexec,loop image.disk1
> /mnt/analysis
Previously I specifically asked you to explain "how you are currently
mounting raw disk images unders Windows using Cygwin."
This answer confirms my suspicions that you are currently not doing this /at
all/.
Your command:
"mount -t vfat -o ro,noexec,loop image.disk1 /mnt/analysis"
has several problems. The -t option in Cygwin mount doesn't take arguments
- it gives text files under that mountpoint CRLF endings (Windows style).
The -o option doesn't take any of the three arguments passed above.
From the man page for Cygwin's mount:
"The -o option is the method via which various options about the mount
point may be recorded. The following options are available (note that most
of the options are duplicates of other mount flags):
user - mount lives user-specific mount
system - mount lives in system table (default)
binary - files default to binary mode (default)
text - files default to CRLF text mode line endings
exec - files below mount point are all executable
notexec - files below mount point are not executable
cygexec - files below mount point are all cygwin executables
nosuid - no suid files are allowed (currently unimplemented)
managed - directory is managed by cygwin. Mixed case and special
characters in filenames are allowed."
Finally, Cygwin mount is expecting a win32 style path where you have the
"image.disk1" argument.
The extent of use of the Cygwin mount command is mapping Win32 paths to
POSIX style paths, for example:
"mount c:\foo\bar /foo/bar"
So, I ask again, how you are currently mounting raw disk images unders
Windows using Cygwin?
To answer the original poster, the only tool I've actually seen used on
Windows to do this is Mount Image Pro:
http://www.mountimage.com/
Although the aforementioned FileDisk appears interesting.
Cory Altheide
Senior Network Forensics Specialist
NNSA Information Assurance Response Center (IARC)
alt...@nv...
"I have taken all knowledge to be my province." -- Francis Bacon
> --- "Altheide, Cory B. (IARC)" <Alt...@nv...>
> wrote:
>
> > Hi -
> >
> > I'd be interested in either one (or both) of you
> > explaining how you are
> > currently mounting raw disk images under Windows
> > using Cygwin.
> >
> > Thanks -
> >
> > Cory Altheide
> > Senior Network Forensics Specialist
> > NNSA Information Assurance Response Center (IARC)
> > alt...@nv...
> > "I have taken all knowledge to be my province." --
> > Francis Bacon
> >
> > > -----Original Message-----
> > > From: sle...@li...
> > >
> > [mailto:sle...@li...]
> > On
> > > Behalf Of youcef bichbiche
> > > Sent: Saturday, June 11, 2005 4:23 PM
> > > To: sle...@li...
> > > Subject: Re: [sleuthkit-users] Mounting a dd image
> > under windows
> > >
> > >
> > > Try Cygwin. it supports Sleuthkit too.
> > >
> > > --- esrkq yahoo <es...@ya...> wrote:
> > >
> > > > Hi Guys,
> > > > slightly off topic but does anyone know of a
> > utility
> > > > that will mount a dd image under windows xp.
> >
> >
> >
> >
> -------------------------------------------------------
> > This SF.Net email is sponsored by: NEC IT Guy Games.
> > How far can you shotput
> > a projector? How fast can you ride your desk chair
> > down the office luge track?
> > If you want to score the big prize, get to know the
> > little guy.
> > Play to win an NEC 61" plasma display:
> > http://www.necitguy.com/?r=20
> > _______________________________________________
> > sleuthkit-users mailing list
> >
> https://lists.sourceforge.net/lists/listinfo/sleuthkit-users
> > http://www.sleuthkit.org
> >
>
>
>
>
>
>
> ___________________________________________________________
> Yahoo! Messenger - NEW crystal clear PC to PC calling
> worldwide with voicemail http://uk.messenger.yahoo.com
>
|
|
From: youcef b. <ybi...@ya...> - 2005-06-13 23:48:47
|
Hi, It uses the concept of a loopback device, which allows to mount a file system within an image file. to do that you use the mount command with the loop option to indicate that you want to use the loop device to mount the file system within the image, and you specifiy a disk image rather than a disk device. Example: mount -t vfat -o ro,noexec,loop image.disk1 /mnt/analysis --- "Altheide, Cory B. (IARC)" <Alt...@nv...> wrote: > Hi - > > I'd be interested in either one (or both) of you > explaining how you are > currently mounting raw disk images under Windows > using Cygwin. > > Thanks - > > Cory Altheide > Senior Network Forensics Specialist > NNSA Information Assurance Response Center (IARC) > alt...@nv... > "I have taken all knowledge to be my province." -- > Francis Bacon > > > -----Original Message----- > > From: sle...@li... > > > [mailto:sle...@li...] > On > > Behalf Of youcef bichbiche > > Sent: Saturday, June 11, 2005 4:23 PM > > To: sle...@li... > > Subject: Re: [sleuthkit-users] Mounting a dd image > under windows > > > > > > Try Cygwin. it supports Sleuthkit too. > > > > --- esrkq yahoo <es...@ya...> wrote: > > > > > Hi Guys, > > > slightly off topic but does anyone know of a > utility > > > that will mount a dd image under windows xp. > > > > ------------------------------------------------------- > This SF.Net email is sponsored by: NEC IT Guy Games. > How far can you shotput > a projector? How fast can you ride your desk chair > down the office luge track? > If you want to score the big prize, get to know the > little guy. > Play to win an NEC 61" plasma display: > http://www.necitguy.com/?r=20 > _______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org > ___________________________________________________________ Yahoo! Messenger - NEW crystal clear PC to PC calling worldwide with voicemail http://uk.messenger.yahoo.com |
|
From: Altheide, C. B. (IARC) <Alt...@nv...> - 2005-06-13 17:24:49
|
Hi - I'd be interested in either one (or both) of you explaining how you are currently mounting raw disk images under Windows using Cygwin. Thanks - Cory Altheide Senior Network Forensics Specialist NNSA Information Assurance Response Center (IARC) alt...@nv... "I have taken all knowledge to be my province." -- Francis Bacon > -----Original Message----- > From: sle...@li... > [mailto:sle...@li...] On > Behalf Of youcef bichbiche > Sent: Saturday, June 11, 2005 4:23 PM > To: sle...@li... > Subject: Re: [sleuthkit-users] Mounting a dd image under windows > > > Try Cygwin. it supports Sleuthkit too. > > --- esrkq yahoo <es...@ya...> wrote: > > > Hi Guys, > > slightly off topic but does anyone know of a utility > > that will mount a dd image under windows xp. |
|
From: OFD L. S. D. <DSc...@of...> - 2005-06-13 06:41:08
|
>Hi Guys, Hi, >slightly off topic but does anyone know of a utility >that will mount a dd image under windows xp. Try FileDisk (http://www.acc.umu.se/%7Ebosse/) Dennis |
|
From: Robert-Jan M. <ro...@mo...> - 2005-06-12 13:50:09
|
You can mount dd images with cygwin or commercial with mountimage pro. www.mountimage.com. You have to buy it! sle...@li... wrote: > Send sleuthkit-users mailing list submissions to > sle...@li... > > To subscribe or unsubscribe via the World Wide Web, visit > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > or, via email, send a message with subject or body 'help' to > sle...@li... > > You can reach the person managing the list at > sle...@li... > > When replying, please edit your Subject line so it is more specific > than "Re: Contents of sleuthkit-users digest..." > > > Today's Topics: > > 1. Mounting a dd image under windows (esrkq yahoo) > 2. Re: Mounting a dd image under windows (youcef bichbiche) > > --__--__-- > > Message: 1 > Date: Sat, 11 Jun 2005 17:43:21 +0100 (BST) > From: esrkq yahoo <es...@ya...> > To: sle...@li... > Subject: [sleuthkit-users] Mounting a dd image under windows > > Hi Guys, > slightly off topic but does anyone know of a utility > that will mount a dd image under windows xp. > > Thanks, > JP > > > > ___________________________________________________________ > How much free photo storage do you get? Store your holiday > snaps for FREE with Yahoo! Photos http://uk.photos.yahoo.com > > > --__--__-- > > Message: 2 > Date: Sun, 12 Jun 2005 00:22:55 +0100 (BST) > From: youcef bichbiche <ybi...@ya...> > Subject: Re: [sleuthkit-users] Mounting a dd image under windows > To: sle...@li... > > Try Cygwin. it supports Sleuthkit too. > > --- esrkq yahoo <es...@ya...> wrote: > > >>Hi Guys, >>slightly off topic but does anyone know of a utility >>that will mount a dd image under windows xp. >> >>Thanks, >>JP >> >> >> >> > > ___________________________________________________________ > >>How much free photo storage do you get? Store your >>holiday >>snaps for FREE with Yahoo! Photos >>http://uk.photos.yahoo.com >> >> >> > > ------------------------------------------------------- > >>This SF.Net email is sponsored by: NEC IT Guy Games. >> How far can you shotput >>a projector? How fast can you ride your desk chair >>down the office luge track? >>If you want to score the big prize, get to know the >>little guy. >>Play to win an NEC 61" plasma display: >>http://www.necitguy.com/?r=20 >>_______________________________________________ >>sleuthkit-users mailing list >> > > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > >>http://www.sleuthkit.org >> > > > > > > ___________________________________________________________ > How much free photo storage do you get? Store your holiday > snaps for FREE with Yahoo! Photos http://uk.photos.yahoo.com > > > > --__--__-- > > _______________________________________________ > sleuthkit-users mailing list > sle...@li... > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > > > End of sleuthkit-users Digest > |