sleuthkit-users Mailing List for The Sleuth Kit (Page 31)
Brought to you by:
carrier
You can subscribe to this list here.
2002 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
(6) |
Aug
|
Sep
(11) |
Oct
(5) |
Nov
(4) |
Dec
|
---|---|---|---|---|---|---|---|---|---|---|---|---|
2003 |
Jan
(1) |
Feb
(20) |
Mar
(60) |
Apr
(40) |
May
(24) |
Jun
(28) |
Jul
(18) |
Aug
(27) |
Sep
(6) |
Oct
(14) |
Nov
(15) |
Dec
(22) |
2004 |
Jan
(34) |
Feb
(13) |
Mar
(28) |
Apr
(23) |
May
(27) |
Jun
(26) |
Jul
(37) |
Aug
(19) |
Sep
(20) |
Oct
(39) |
Nov
(17) |
Dec
(9) |
2005 |
Jan
(45) |
Feb
(43) |
Mar
(66) |
Apr
(36) |
May
(19) |
Jun
(64) |
Jul
(10) |
Aug
(11) |
Sep
(35) |
Oct
(6) |
Nov
(4) |
Dec
(13) |
2006 |
Jan
(52) |
Feb
(34) |
Mar
(39) |
Apr
(39) |
May
(37) |
Jun
(15) |
Jul
(13) |
Aug
(48) |
Sep
(9) |
Oct
(10) |
Nov
(47) |
Dec
(13) |
2007 |
Jan
(25) |
Feb
(4) |
Mar
(2) |
Apr
(29) |
May
(11) |
Jun
(19) |
Jul
(13) |
Aug
(15) |
Sep
(30) |
Oct
(12) |
Nov
(10) |
Dec
(13) |
2008 |
Jan
(2) |
Feb
(54) |
Mar
(58) |
Apr
(43) |
May
(10) |
Jun
(27) |
Jul
(25) |
Aug
(27) |
Sep
(48) |
Oct
(69) |
Nov
(55) |
Dec
(43) |
2009 |
Jan
(26) |
Feb
(36) |
Mar
(28) |
Apr
(27) |
May
(55) |
Jun
(9) |
Jul
(19) |
Aug
(16) |
Sep
(15) |
Oct
(17) |
Nov
(70) |
Dec
(21) |
2010 |
Jan
(56) |
Feb
(59) |
Mar
(53) |
Apr
(32) |
May
(25) |
Jun
(31) |
Jul
(36) |
Aug
(11) |
Sep
(37) |
Oct
(19) |
Nov
(23) |
Dec
(6) |
2011 |
Jan
(21) |
Feb
(20) |
Mar
(30) |
Apr
(30) |
May
(74) |
Jun
(50) |
Jul
(34) |
Aug
(34) |
Sep
(12) |
Oct
(33) |
Nov
(10) |
Dec
(8) |
2012 |
Jan
(23) |
Feb
(57) |
Mar
(26) |
Apr
(14) |
May
(27) |
Jun
(27) |
Jul
(60) |
Aug
(88) |
Sep
(13) |
Oct
(36) |
Nov
(97) |
Dec
(85) |
2013 |
Jan
(60) |
Feb
(24) |
Mar
(43) |
Apr
(32) |
May
(22) |
Jun
(38) |
Jul
(51) |
Aug
(50) |
Sep
(76) |
Oct
(65) |
Nov
(25) |
Dec
(30) |
2014 |
Jan
(19) |
Feb
(41) |
Mar
(43) |
Apr
(28) |
May
(61) |
Jun
(12) |
Jul
(10) |
Aug
(37) |
Sep
(76) |
Oct
(31) |
Nov
(41) |
Dec
(12) |
2015 |
Jan
(33) |
Feb
(28) |
Mar
(53) |
Apr
(22) |
May
(29) |
Jun
(20) |
Jul
(15) |
Aug
(17) |
Sep
(52) |
Oct
(3) |
Nov
(18) |
Dec
(21) |
2016 |
Jan
(20) |
Feb
(8) |
Mar
(21) |
Apr
(7) |
May
(13) |
Jun
(35) |
Jul
(34) |
Aug
(11) |
Sep
(14) |
Oct
(22) |
Nov
(31) |
Dec
(23) |
2017 |
Jan
(20) |
Feb
(7) |
Mar
(5) |
Apr
(6) |
May
(6) |
Jun
(22) |
Jul
(11) |
Aug
(16) |
Sep
(8) |
Oct
(1) |
Nov
(1) |
Dec
(1) |
2018 |
Jan
|
Feb
|
Mar
(16) |
Apr
(2) |
May
(6) |
Jun
(5) |
Jul
|
Aug
(2) |
Sep
(4) |
Oct
|
Nov
(16) |
Dec
(13) |
2019 |
Jan
|
Feb
(1) |
Mar
(25) |
Apr
(9) |
May
(2) |
Jun
(1) |
Jul
(1) |
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
2020 |
Jan
(2) |
Feb
|
Mar
(1) |
Apr
|
May
(1) |
Jun
(3) |
Jul
(2) |
Aug
|
Sep
|
Oct
(5) |
Nov
|
Dec
|
2021 |
Jan
|
Feb
|
Mar
(1) |
Apr
|
May
|
Jun
(4) |
Jul
(1) |
Aug
|
Sep
(1) |
Oct
|
Nov
(1) |
Dec
|
2022 |
Jan
|
Feb
(2) |
Mar
|
Apr
|
May
(2) |
Jun
|
Jul
(3) |
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
2023 |
Jan
(2) |
Feb
|
Mar
(1) |
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
(1) |
Nov
|
Dec
|
2024 |
Jan
|
Feb
(3) |
Mar
|
Apr
(1) |
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
2025 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
(1) |
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
From: Brian C. <ca...@sl...> - 2015-02-17 15:50:48
|
Hi Alan, It will be part of the next release (which will be either end of this week or early next week). brian On Feb 17, 2015, at 4:29 AM, Alan Browne <ala...@gm...> wrote: > Hi all > > I was looking at the the available modules written for autopsy and I have noticed the code for photorec carver module. I have noticed that in the presentation given by Richard Cordovano in python autopsy that the photorec carving module is compiled and installed into autopsy (screen shot attached). > Unfortunately my knowledge of java and netbeans is limited to say the least so I am unable to compile the module from source to test it. > > Is the photorec module working? > Is the compiled version of photorec carver available to me? > Or is it possible for someone to walk me through on how I can compile the module from source. > > Regards > > Alan > ------------------------------------------------------------------------------ > Download BIRT iHub F-Type - The Free Enterprise-Grade BIRT Server > from Actuate! Instantly Supercharge Your Business Reports and Dashboards > with Interactivity, Sharing, Native Excel Exports, App Integration & more > Get technology previously reserved for billion-dollar corporations, FREE > http://pubads.g.doubleclick.net/gampad/clk?id=190641631&iu=/4140/ostg.clktrk_______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org |
From: Alan B. <ala...@gm...> - 2015-02-17 09:31:03
|
Hi all I was looking at the the available modules written for autopsy and I have noticed the code for photorec carver module. I have noticed that in the presentation given by Richard Cordovano in python autopsy that the photorec carving module is compiled and installed into autopsy (screen shot attached). Unfortunately my knowledge of java and netbeans is limited to say the least so I am unable to compile the module from source to test it. Is the photorec module working? Is the compiled version of photorec carver available to me? Or is it possible for someone to walk me through on how I can compile the module from source. Regards |
From: Alan B. <ala...@gm...> - 2015-02-17 09:29:44
|
Hi all I was looking at the the available modules written for autopsy and I have noticed the code for photorec carver module. I have noticed that in the presentation given by Richard Cordovano in python autopsy that the photorec carving module is compiled and installed into autopsy (screen shot attached). Unfortunately my knowledge of java and netbeans is limited to say the least so I am unable to compile the module from source to test it. Is the photorec module working? Is the compiled version of photorec carver available to me? Or is it possible for someone to walk me through on how I can compile the module from source. Regards Alan |
From: Nanni B. <dig...@gm...> - 2015-02-16 09:53:19
|
Hi Brian, I checked the timeline module, maybe I'm hard to change my mind, but I would to have another view...the old view of the timeline. I try to explain better, I would like to see all the files sorted in ascending or descending mode in a time range, (e.g. in the CSV view) and finally I would like to export the results. Maybe, I miss something, but I cannot export the timeline in Autopsy 3.1.1. This is my opinion ;) Thank you -- Dr. Nanni Bassetti http://www.nannibassetti.com CAINE project manager - http://www.caine-live.net |
From: Brian C. <ca...@sl...> - 2015-02-16 03:29:29
|
Hello, I realized the other day that we never really publicized a tutorial video that we made for the timeline module that came with Autopsy 3.1.1. it is now embedded on the timeline page (http://www.sleuthkit.org/autopsy/timeline.php). We're about to start working on the module again and if you have any feedback on it, then let us know. thanks, brian |
From: Willi B. <wil...@gm...> - 2015-02-09 22:22:25
|
Approximately 1.5 years ago I got Autopsy building under Ubuntu Linux. Since then things may have changed, but you can still review the steps I documented here: http://www.williballenthin.com/blog/2013/08/06/wip-running-autopsy-3-on-linux/ I hope you can use this as a starting point, but I'm afraid I won't be able to provide too much support. Willi On Mon, Feb 9, 2015 at 5:09 PM, Harland Yu <hf...@gm...> wrote: > Hi, > > I'm interested in testing Autopsy 3 on Linux, seeing as it's a Java-based > project. One roadblock is that I'm having trouble getting the Java/JNI > libraries from TSK to compile on a Slackware64 14.1 machine. It seems to be > the same issue as > http://sourceforge.net/p/sleuthkit/mailman/message/32272481/. > > I have Apache Ant (1.9.4) and Java (1.8.0_31) installed, yet the configure > script refuses to allow the JNI bindings to be built. > > Any help would be greatly appreciated. Snipped output of configure below. > > ... > checking for java... java > checking for uudecode... yes > checking if uudecode can decode base 64 file... yes > checking if java works... yes > checking for ant... /usr/local/bin/ant > configure: creating ./config.status > config.status: creating Makefile > ... > configure: > Building: > afflib support: yes > libewf support: yes > zlib support: yes > > Features: > Java/JNI support: no > > > Thanks, > > Harland > > > ------------------------------------------------------------------------------ > Dive into the World of Parallel Programming. The Go Parallel Website, > sponsored by Intel and developed in partnership with Slashdot Media, is > your > hub for all things parallel software development, from weekly thought > leadership blogs to news, videos, case studies, tutorials and more. Take a > look and join the conversation now. http://goparallel.sourceforge.net/ > _______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org > > |
From: Harland Yu <hf...@gm...> - 2015-02-09 22:09:38
|
Hi, I'm interested in testing Autopsy 3 on Linux, seeing as it's a Java-based project. One roadblock is that I'm having trouble getting the Java/JNI libraries from TSK to compile on a Slackware64 14.1 machine. It seems to be the same issue as http://sourceforge.net/p/sleuthkit/mailman/message/32272481/. I have Apache Ant (1.9.4) and Java (1.8.0_31) installed, yet the configure script refuses to allow the JNI bindings to be built. Any help would be greatly appreciated. Snipped output of configure below. ... checking for java... java checking for uudecode... yes checking if uudecode can decode base 64 file... yes checking if java works... yes checking for ant... /usr/local/bin/ant configure: creating ./config.status config.status: creating Makefile ... configure: Building: afflib support: yes libewf support: yes zlib support: yes Features: Java/JNI support: no Thanks, Harland |
From: Jose N. H. <jo...@jn...> - 2015-02-03 20:58:43
|
Yes, of course. I need a coffee... Thanks! On Tue, Feb 3, 2015 at 8:19 PM, Alex Nelson <ajn...@cs...> wrote: > By "order," do you mean "command"? > > If so, then it seems you don't have the compiler g++ installed. Note that > g++ is packaged separately from gcc, at least in Ubuntu. > > If you'd like a list of packages that gets you what you need to build TSK > from scratch, this script will take care of you: > > > https://github.com/ajnelson/regxml_extractor/blob/unstable/deps/install_dependent_packages-ubuntu-14.04.sh > > That script is tested in Ubuntu 14.04. It does include a bit more than > you'd need; for instance, you probably don't want ocaml. But if installing > g++ alone leaves you with more dependencies to fulfill, that list will more > than take care of your needs. > > --Alex > > > > On Tue, Feb 3, 2015 at 2:07 PM, Jose Navarro Hernández <jo...@jn...> > wrote: > >> Hi all. >> >> I have just installed a new stable debian 7.8.0: >> >> # uname -a >> >> Linux server 3.2.0-4-amd64 #1 SMP Debian 3.2.65-1+deb7u1 x86_64 GNU/Linux >> >> >> and downloaded source code for sleuthkit-4.1.3. ./configure ends >> flawlessly, but make ends with this error: >> >> source='tsk_error_win32.cpp' object='tsk_error_win32.lo' libtool=yes \ >> >> DEPDIR=.deps depmode=none /bin/bash ../../config/depcomp \ >> >> /bin/bash ../../libtool --tag=CXX --mode=compile g++ -DHAVE_CONFIG_H >> -I. -I../../tsk -I../.. -Wall -pthread -I/usr/local/include -c -o >> tsk_error_win32.lo tsk_error_win32.cpp >> >> libtool: compile: g++ -DHAVE_CONFIG_H -I. -I../../tsk -I../.. -Wall >> -pthread -I/usr/local/include -c tsk_error_win32.cpp -o >> .libs/tsk_error_win32.o >> >> ../../libtool: línea 981: g++: no se encontró la orden >> >> >> Sorry for the spanish. Basically says, >> >> '../../libtool: línea 981: g++: order not found' >> >> >> I have reproduced the problem with sleuthkit 4.1.2 and 4.0.0. >> >> Anyone has found the same problem? >> >> Thanks in advance >> >> >> ------------------------------------------------------------------------------ >> Dive into the World of Parallel Programming. The Go Parallel Website, >> sponsored by Intel and developed in partnership with Slashdot Media, is >> your >> hub for all things parallel software development, from weekly thought >> leadership blogs to news, videos, case studies, tutorials and more. Take a >> look and join the conversation now. http://goparallel.sourceforge.net/ >> _______________________________________________ >> sleuthkit-users mailing list >> https://lists.sourceforge.net/lists/listinfo/sleuthkit-users >> http://www.sleuthkit.org >> >> > |
From: Alex N. <ajn...@cs...> - 2015-02-03 19:47:22
|
By "order," do you mean "command"? If so, then it seems you don't have the compiler g++ installed. Note that g++ is packaged separately from gcc, at least in Ubuntu. If you'd like a list of packages that gets you what you need to build TSK from scratch, this script will take care of you: https://github.com/ajnelson/regxml_extractor/blob/unstable/deps/install_dependent_packages-ubuntu-14.04.sh That script is tested in Ubuntu 14.04. It does include a bit more than you'd need; for instance, you probably don't want ocaml. But if installing g++ alone leaves you with more dependencies to fulfill, that list will more than take care of your needs. --Alex On Tue, Feb 3, 2015 at 2:07 PM, Jose Navarro Hernández <jo...@jn...> wrote: > Hi all. > > I have just installed a new stable debian 7.8.0: > > # uname -a > > Linux server 3.2.0-4-amd64 #1 SMP Debian 3.2.65-1+deb7u1 x86_64 GNU/Linux > > > and downloaded source code for sleuthkit-4.1.3. ./configure ends > flawlessly, but make ends with this error: > > source='tsk_error_win32.cpp' object='tsk_error_win32.lo' libtool=yes \ > > DEPDIR=.deps depmode=none /bin/bash ../../config/depcomp \ > > /bin/bash ../../libtool --tag=CXX --mode=compile g++ -DHAVE_CONFIG_H -I. > -I../../tsk -I../.. -Wall -pthread -I/usr/local/include -c -o > tsk_error_win32.lo tsk_error_win32.cpp > > libtool: compile: g++ -DHAVE_CONFIG_H -I. -I../../tsk -I../.. -Wall > -pthread -I/usr/local/include -c tsk_error_win32.cpp -o > .libs/tsk_error_win32.o > > ../../libtool: línea 981: g++: no se encontró la orden > > > Sorry for the spanish. Basically says, > > '../../libtool: línea 981: g++: order not found' > > > I have reproduced the problem with sleuthkit 4.1.2 and 4.0.0. > > Anyone has found the same problem? > > Thanks in advance > > > ------------------------------------------------------------------------------ > Dive into the World of Parallel Programming. The Go Parallel Website, > sponsored by Intel and developed in partnership with Slashdot Media, is > your > hub for all things parallel software development, from weekly thought > leadership blogs to news, videos, case studies, tutorials and more. Take a > look and join the conversation now. http://goparallel.sourceforge.net/ > _______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org > > |
From: Jose N. H. <jo...@jn...> - 2015-02-03 19:07:24
|
Hi all. I have just installed a new stable debian 7.8.0: # uname -a Linux server 3.2.0-4-amd64 #1 SMP Debian 3.2.65-1+deb7u1 x86_64 GNU/Linux and downloaded source code for sleuthkit-4.1.3. ./configure ends flawlessly, but make ends with this error: source='tsk_error_win32.cpp' object='tsk_error_win32.lo' libtool=yes \ DEPDIR=.deps depmode=none /bin/bash ../../config/depcomp \ /bin/bash ../../libtool --tag=CXX --mode=compile g++ -DHAVE_CONFIG_H -I. -I../../tsk -I../.. -Wall -pthread -I/usr/local/include -c -o tsk_error_win32.lo tsk_error_win32.cpp libtool: compile: g++ -DHAVE_CONFIG_H -I. -I../../tsk -I../.. -Wall -pthread -I/usr/local/include -c tsk_error_win32.cpp -o .libs/tsk_error_win32.o ../../libtool: línea 981: g++: no se encontró la orden Sorry for the spanish. Basically says, '../../libtool: línea 981: g++: order not found' I have reproduced the problem with sleuthkit 4.1.2 and 4.0.0. Anyone has found the same problem? Thanks in advance |
From: Dennis Z. <de...@es...> - 2015-01-31 08:47:55
|
This is the SD card: Disk /dev/sdb: 59.5 GiB, 63864569856 bytes, 124735488 sectors Units: sectors of 1 * 512 = 512 bytes Sector size (logical/physical): 512 bytes / 512 bytes I/O size (minimum/optimal): 512 bytes / 512 bytes Disklabel type: dos Disk identifier: 0x00000000 Device Boot Start End Sectors Size Id Type /dev/sdb1 * 2048 124735487 124733440 59.5G c W95 FAT32 (LBA) And this is the partition it self: Disk /dev/sdb1: 59.5 GiB, 63863521280 bytes, 124733440 sectors Units: sectors of 1 * 512 = 512 bytes Sector size (logical/physical): 512 bytes / 512 bytes I/O size (minimum/optimal): 512 bytes / 512 bytes Disklabel type: dos Disk identifier: 0xf4f4f4f4 Device Boot Start End Sectors Size Id Type /dev/sdb1p1 ? 4109694196 8219388391 4109694196 1.9T f4 SpeedStor /dev/sdb1p2 ? 4109694196 8219388391 4109694196 1.9T f4 SpeedStor /dev/sdb1p3 ? 4109694196 8219388391 4109694196 1.9T f4 SpeedStor /dev/sdb1p4 ? 4109694196 8219388391 4109694196 1.9T f4 SpeedStor On Sat, Jan 31, 2015 at 10:29 AM, Dennis Zheleznyak <de...@es...> wrote: > Thanks again for the quick response and help ! > > I downloaded both 4.20 and development versions and compiled it using: > > ./configure --prefix=/usr/local/sl >> ./configure --prefix=/usr/local/sldevelop >> make -j 4 >> make install > > > I get the same result as before, anything I can do to fix it ? > > > > On Sat, Jan 31, 2015 at 6:26 AM, Kalin KOZHUHAROV <me....@gm...> > wrote: > >> On Sat, Jan 31, 2015 at 11:27 AM, Dennis Zheleznyak >> <de...@es...> wrote: >> > The Sleuth Kit ver 4.1.3 >> > >> https://github.com/sleuthkit/sleuthkit/releases >> >> 4.1.3 was released Jan 2014 and has no support for exFAT... >> >> You'll need to compile either possibly upcoming 4.2.0 >> https://github.com/sleuthkit/sleuthkit/tree/release-4.2.0/ or the >> develop branch https://github.com/sleuthkit/sleuthkit/tree/develop/ >> >> You can always check your current support with `-f list` option, like >> `fls -f list`. >> >> Cheers, >> Kalin. >> > > |
From: Dennis Z. <de...@es...> - 2015-01-31 08:29:13
|
Thanks again for the quick response and help ! I downloaded both 4.20 and development versions and compiled it using: ./configure --prefix=/usr/local/sl > ./configure --prefix=/usr/local/sldevelop > make -j 4 > make install I get the same result as before, anything I can do to fix it ? On Sat, Jan 31, 2015 at 6:26 AM, Kalin KOZHUHAROV <me....@gm...> wrote: > On Sat, Jan 31, 2015 at 11:27 AM, Dennis Zheleznyak > <de...@es...> wrote: > > The Sleuth Kit ver 4.1.3 > > > https://github.com/sleuthkit/sleuthkit/releases > > 4.1.3 was released Jan 2014 and has no support for exFAT... > > You'll need to compile either possibly upcoming 4.2.0 > https://github.com/sleuthkit/sleuthkit/tree/release-4.2.0/ or the > develop branch https://github.com/sleuthkit/sleuthkit/tree/develop/ > > You can always check your current support with `-f list` option, like > `fls -f list`. > > Cheers, > Kalin. > |
From: Kalin K. <me....@gm...> - 2015-01-31 04:26:52
|
On Sat, Jan 31, 2015 at 11:27 AM, Dennis Zheleznyak <de...@es...> wrote: > The Sleuth Kit ver 4.1.3 > https://github.com/sleuthkit/sleuthkit/releases 4.1.3 was released Jan 2014 and has no support for exFAT... You'll need to compile either possibly upcoming 4.2.0 https://github.com/sleuthkit/sleuthkit/tree/release-4.2.0/ or the develop branch https://github.com/sleuthkit/sleuthkit/tree/develop/ You can always check your current support with `-f list` option, like `fls -f list`. Cheers, Kalin. |
From: Dennis Z. <de...@es...> - 2015-01-31 02:33:48
|
0100000: eb76 9045 5846 4154 2020 2000 0000 0000 .v.EXFAT ..... On Sat, Jan 31, 2015 at 4:28 AM, Tim Hoffecker <tho...@gm...> wrote: > What does the VBR look like > > xxd -l 512 -s 1048576 disk.img > > On Jan 30, 2015, at 9:17 PM, Dennis Zheleznyak <de...@es...> > wrote: > > Tried that: > [root@localhost bin]# ./fls -o 2048 /home/dennis/Documents/disk.img > Cannot determine file system type > > > On Sat, Jan 31, 2015 at 4:14 AM, Kalin KOZHUHAROV <me....@gm...> > wrote: > >> >> On Jan 31, 2015 11:11 AM, "Dennis Zheleznyak" <de...@es...> >> wrote: >> > [root@localhost bin]# ./mmls /home/dennis/Documents/disk.img >> > DOS Partition Table >> > Offset Sector: 0 >> > Units are in 512-byte sectors >> > >> > Slot Start End Length Description >> > 00: Meta 0000000000 0000000000 0000000001 Primary Table (#0) >> > 01: ----- 0000000000 0000002047 0000002048 Unallocated >> > 02: 00:00 0000002048 0124735487 0124733440 Win95 FAT32 (0x0c) >> > >> > >> So add -o 2048 to that fls command. >> >> Kalin. >> > > > ------------------------------------------------------------------------------ > Dive into the World of Parallel Programming. The Go Parallel Website, > sponsored by Intel and developed in partnership with Slashdot Media, is > your > hub for all things parallel software development, from weekly thought > leadership blogs to news, videos, case studies, tutorials and more. Take a > look and join the conversation now. > http://goparallel.sourceforge.net/_______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org > > > |
From: Dennis Z. <de...@es...> - 2015-01-31 02:27:35
|
The Sleuth Kit ver 4.1.3 On Sat, Jan 31, 2015 at 4:26 AM, Kalin KOZHUHAROV <me....@gm...> wrote: > Hmm support was added around July last year.. what is your version? > > Kalin. > |
From: Kalin K. <me....@gm...> - 2015-01-31 02:26:51
|
Hmm support was added around July last year.. what is your version? Kalin. |
From: Dennis Z. <de...@es...> - 2015-01-31 02:17:20
|
Tried that: [root@localhost bin]# ./fls -o 2048 /home/dennis/Documents/disk.img Cannot determine file system type On Sat, Jan 31, 2015 at 4:14 AM, Kalin KOZHUHAROV <me....@gm...> wrote: > > On Jan 31, 2015 11:11 AM, "Dennis Zheleznyak" <de...@es...> > wrote: > > [root@localhost bin]# ./mmls /home/dennis/Documents/disk.img > > DOS Partition Table > > Offset Sector: 0 > > Units are in 512-byte sectors > > > > Slot Start End Length Description > > 00: Meta 0000000000 0000000000 0000000001 Primary Table (#0) > > 01: ----- 0000000000 0000002047 0000002048 Unallocated > > 02: 00:00 0000002048 0124735487 0124733440 Win95 FAT32 (0x0c) > > > > > So add -o 2048 to that fls command. > > Kalin. > |
From: Kalin K. <me....@gm...> - 2015-01-31 02:15:05
|
On Jan 31, 2015 11:11 AM, "Dennis Zheleznyak" <de...@es...> wrote: > [root@localhost bin]# ./mmls /home/dennis/Documents/disk.img > DOS Partition Table > Offset Sector: 0 > Units are in 512-byte sectors > > Slot Start End Length Description > 00: Meta 0000000000 0000000000 0000000001 Primary Table (#0) > 01: ----- 0000000000 0000002047 0000002048 Unallocated > 02: 00:00 0000002048 0124735487 0124733440 Win95 FAT32 (0x0c) > > So add -o 2048 to that fls command. Kalin. |
From: Dennis Z. <de...@es...> - 2015-01-31 02:11:59
|
Hi, Thanks for the fast response ! [root@localhost bin]# ./mmls /home/dennis/Documents/disk.img DOS Partition Table Offset Sector: 0 Units are in 512-byte sectors Slot Start End Length Description 00: Meta 0000000000 0000000000 0000000001 Primary Table (#0) 01: ----- 0000000000 0000002047 0000002048 Unallocated 02: 00:00 0000002048 0124735487 0124733440 Win95 FAT32 (0x0c) On Sat, Jan 31, 2015 at 4:08 AM, Kalin KOZHUHAROV <me....@gm...> wrote: > > On Jan 31, 2015 10:41 AM, "Dennis Zheleznyak" <de...@es...> > wrote: > > I'm trying to recover deleted data from an SD card that I pulled out of > a smartphone. > > > > I backed up the image using: > > > >> dd if=/dev/sdb of=/tmp/disk.img > > > > > > However, when I try to recover the files using the following command: > > > >> usr/local/sleuthkit/bin/fls -r -p disk.img | less > > > > > > I get the following error: > > > >> Cannot determine file system type > > > > > Not sure exfat is supported and cannot test right now, but what is the > output of `mmls disk.img` > > May be you need offset (it used partitions) ? > > Kalin. > |
From: Kalin K. <me....@gm...> - 2015-01-31 02:08:23
|
On Jan 31, 2015 10:41 AM, "Dennis Zheleznyak" <de...@es...> wrote: > I'm trying to recover deleted data from an SD card that I pulled out of a smartphone. > > I backed up the image using: > >> dd if=/dev/sdb of=/tmp/disk.img > > > However, when I try to recover the files using the following command: > >> usr/local/sleuthkit/bin/fls -r -p disk.img | less > > > I get the following error: > >> Cannot determine file system type > > Not sure exfat is supported and cannot test right now, but what is the output of `mmls disk.img` May be you need offset (it used partitions) ? Kalin. |
From: Dennis Z. <de...@es...> - 2015-01-31 01:40:33
|
Hi, I'm trying to recover deleted data from an SD card that I pulled out of a smartphone. I backed up the image using: dd if=/dev/sdb of=/tmp/disk.img However, when I try to recover the files using the following command: usr/local/sleuthkit/bin/fls -r -p disk.img | less I get the following error: Cannot determine file system type Fdisk shows that it's a WN95 FAT32. Thank you, Dennis. |
From: Don L. <do...@se...> - 2015-01-29 14:28:25
|
Thank you Brian. I actually just figured that out this morning. It seems to have worked well. Don L. -----Original Message----- From: Brian Carrier [mailto:ca...@sl...] Sent: Thursday, January 29, 2015 7:20 AM To: Don Lewis Cc: 'sle...@li...' Subject: Re: [sleuthkit-users] Autopsy 3 Import Encase .hash files Hi Don, Yes, you can. Go to Tools -> Options -> Hash Database and then choose "Import Database" on the bottom. You will then need to make an index of the database because the EnCase hash sets aren't sorted. thanks, brian On Jan 28, 2015, at 4:30 PM, Don Lewis <do...@se...> wrote: > Can you import an encase hash file to Autopsy 3 ? > > Thanks, > > Don L. Lewis > High-Tech Crimes Training Specialist > > do...@se... > 916 955 6119 > > SEARCH Group Inc. > The National Consortium for Justice Information and Statistics > 7311 Greenhaven Drive, Suite 270 > Sacramento, California 95831 > > ---------------------------------------------------------------------- > -------- Dive into the World of Parallel Programming. The Go Parallel > Website, sponsored by Intel and developed in partnership with Slashdot > Media, is your hub for all things parallel software development, from > weekly thought leadership blogs to news, videos, case studies, > tutorials and more. Take a look and join the conversation > now.http://goparallel.sourceforge.net/________________________________ > _______________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org |
From: Brian C. <ca...@sl...> - 2015-01-29 14:20:03
|
Hi Don, Yes, you can. Go to Tools -> Options -> Hash Database and then choose "Import Database" on the bottom. You will then need to make an index of the database because the EnCase hash sets aren't sorted. thanks, brian On Jan 28, 2015, at 4:30 PM, Don Lewis <do...@se...> wrote: > Can you import an encase hash file to Autopsy 3 ? > > Thanks, > > Don L. Lewis > High-Tech Crimes Training Specialist > > do...@se... > 916 955 6119 > > SEARCH Group Inc. > The National Consortium for Justice Information and Statistics > 7311 Greenhaven Drive, Suite 270 > Sacramento, California 95831 > > ------------------------------------------------------------------------------ > Dive into the World of Parallel Programming. The Go Parallel Website, > sponsored by Intel and developed in partnership with Slashdot Media, is your > hub for all things parallel software development, from weekly thought > leadership blogs to news, videos, case studies, tutorials and more. Take a > look and join the conversation now.http://goparallel.sourceforge.net/_______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org |
From: Don L. <do...@se...> - 2015-01-28 22:05:50
|
Can you import an encase hash file to Autopsy 3 ? Thanks, Don L. Lewis High-Tech Crimes Training Specialist do...@se...<mailto:do...@se...> 916 955 6119 SEARCH Group Inc. The National Consortium for Justice Information and Statistics 7311 Greenhaven Drive, Suite 270 Sacramento, California 95831 |
From: Ketil F. <ke...@fr...> - 2015-01-25 22:34:39
|
Kai, I see you added the sync Simson suggested, but still no joy? I tried to recreate your example, and it works for me. I tested by creating a simple loopback file with ext4 on it, like this: dd if=/dev/zero of=ext4.dd bs=1M count=200 mkfs -t ext4 ext4.dd and I used tsk 4.1.3 (compiled from github). What file system (and file system options) do you have on /dev/sdb1, and what version of blkcat are you using? Does the block contain any data at all? Add the -h flag to blkcat to see the hex dump of the block, is it all zeros or is there anything else there? Regarding the sync call, I tested with and without it right now with ext4. If the data isn't written out to disk, there's nothing listed under "Direct Blocks" either. Cheers, Ketil On 25 January 2015 at 21:28, Kai Pöritz <ka...@po...> wrote: > Hello sleuthkit folks, > > I try do display the content of a text file with the help of blkcat. But > the output is none. I did sync before. > > # cat /mnt/not-encrypted-disk/sensitive-file.txt sensitive text > # ls -li /mnt/not-encrypted-disk/sensitive-file.txt > 12 -rw-r--r-- 1 root root 15 Jan 24 17:15 > /mnt/not-encrypted-disk/sensitive-file.txt > # istat /dev/sdb1 12 > inode: 12 > Allocated > Group: 0 > Generation Id: 2192492698 > uid / gid: 0 / 0 > mode: rrw-r--r-- > Flags: > size: 15 > num of links: 1 > > Inode Times: > Accessed: 2015-01-24 17:15:58 (CET) > File Modified: 2015-01-24 17:15:27 (CET) > Inode Modified: 2015-01-24 17:15:27 (CET) > > Direct Blocks: > 127754 > # sync > # blkcat /dev/sdb1 127754 > # > > > Souldn't 'blkcat /dev/sdb1 127754 ' display the content of the file? How > do I blkcat the content of the file? Thanks in advance. > > > > ------------------------------------------------------------------------------ > New Year. New Location. New Benefits. New Data Center in Ashburn, VA. > GigeNET is offering a free month of service with a new server in Ashburn. > Choose from 2 high performing configs, both with 100TB of bandwidth. > Higher redundancy.Lower latency.Increased capacity.Completely compliant. > http://p.sf.net/sfu/gigenet > _______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org > -- -Ketil |