sleuthkit-users Mailing List for The Sleuth Kit (Page 56)
Brought to you by:
carrier
You can subscribe to this list here.
2002 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
(6) |
Aug
|
Sep
(11) |
Oct
(5) |
Nov
(4) |
Dec
|
---|---|---|---|---|---|---|---|---|---|---|---|---|
2003 |
Jan
(1) |
Feb
(20) |
Mar
(60) |
Apr
(40) |
May
(24) |
Jun
(28) |
Jul
(18) |
Aug
(27) |
Sep
(6) |
Oct
(14) |
Nov
(15) |
Dec
(22) |
2004 |
Jan
(34) |
Feb
(13) |
Mar
(28) |
Apr
(23) |
May
(27) |
Jun
(26) |
Jul
(37) |
Aug
(19) |
Sep
(20) |
Oct
(39) |
Nov
(17) |
Dec
(9) |
2005 |
Jan
(45) |
Feb
(43) |
Mar
(66) |
Apr
(36) |
May
(19) |
Jun
(64) |
Jul
(10) |
Aug
(11) |
Sep
(35) |
Oct
(6) |
Nov
(4) |
Dec
(13) |
2006 |
Jan
(52) |
Feb
(34) |
Mar
(39) |
Apr
(39) |
May
(37) |
Jun
(15) |
Jul
(13) |
Aug
(48) |
Sep
(9) |
Oct
(10) |
Nov
(47) |
Dec
(13) |
2007 |
Jan
(25) |
Feb
(4) |
Mar
(2) |
Apr
(29) |
May
(11) |
Jun
(19) |
Jul
(13) |
Aug
(15) |
Sep
(30) |
Oct
(12) |
Nov
(10) |
Dec
(13) |
2008 |
Jan
(2) |
Feb
(54) |
Mar
(58) |
Apr
(43) |
May
(10) |
Jun
(27) |
Jul
(25) |
Aug
(27) |
Sep
(48) |
Oct
(69) |
Nov
(55) |
Dec
(43) |
2009 |
Jan
(26) |
Feb
(36) |
Mar
(28) |
Apr
(27) |
May
(55) |
Jun
(9) |
Jul
(19) |
Aug
(16) |
Sep
(15) |
Oct
(17) |
Nov
(70) |
Dec
(21) |
2010 |
Jan
(56) |
Feb
(59) |
Mar
(53) |
Apr
(32) |
May
(25) |
Jun
(31) |
Jul
(36) |
Aug
(11) |
Sep
(37) |
Oct
(19) |
Nov
(23) |
Dec
(6) |
2011 |
Jan
(21) |
Feb
(20) |
Mar
(30) |
Apr
(30) |
May
(74) |
Jun
(50) |
Jul
(34) |
Aug
(34) |
Sep
(12) |
Oct
(33) |
Nov
(10) |
Dec
(8) |
2012 |
Jan
(23) |
Feb
(57) |
Mar
(26) |
Apr
(14) |
May
(27) |
Jun
(27) |
Jul
(60) |
Aug
(88) |
Sep
(13) |
Oct
(36) |
Nov
(97) |
Dec
(85) |
2013 |
Jan
(60) |
Feb
(24) |
Mar
(43) |
Apr
(32) |
May
(22) |
Jun
(38) |
Jul
(51) |
Aug
(50) |
Sep
(76) |
Oct
(65) |
Nov
(25) |
Dec
(30) |
2014 |
Jan
(19) |
Feb
(41) |
Mar
(43) |
Apr
(28) |
May
(61) |
Jun
(12) |
Jul
(10) |
Aug
(37) |
Sep
(76) |
Oct
(31) |
Nov
(41) |
Dec
(12) |
2015 |
Jan
(33) |
Feb
(28) |
Mar
(53) |
Apr
(22) |
May
(29) |
Jun
(20) |
Jul
(15) |
Aug
(17) |
Sep
(52) |
Oct
(3) |
Nov
(18) |
Dec
(21) |
2016 |
Jan
(20) |
Feb
(8) |
Mar
(21) |
Apr
(7) |
May
(13) |
Jun
(35) |
Jul
(34) |
Aug
(11) |
Sep
(14) |
Oct
(22) |
Nov
(31) |
Dec
(23) |
2017 |
Jan
(20) |
Feb
(7) |
Mar
(5) |
Apr
(6) |
May
(6) |
Jun
(22) |
Jul
(11) |
Aug
(16) |
Sep
(8) |
Oct
(1) |
Nov
(1) |
Dec
(1) |
2018 |
Jan
|
Feb
|
Mar
(16) |
Apr
(2) |
May
(6) |
Jun
(5) |
Jul
|
Aug
(2) |
Sep
(4) |
Oct
|
Nov
(16) |
Dec
(13) |
2019 |
Jan
|
Feb
(1) |
Mar
(25) |
Apr
(9) |
May
(2) |
Jun
(1) |
Jul
(1) |
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
2020 |
Jan
(2) |
Feb
|
Mar
(1) |
Apr
|
May
(1) |
Jun
(3) |
Jul
(2) |
Aug
|
Sep
|
Oct
(5) |
Nov
|
Dec
|
2021 |
Jan
|
Feb
|
Mar
(1) |
Apr
|
May
|
Jun
(4) |
Jul
(1) |
Aug
|
Sep
(1) |
Oct
|
Nov
(1) |
Dec
|
2022 |
Jan
|
Feb
(2) |
Mar
|
Apr
|
May
(2) |
Jun
|
Jul
(3) |
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
2023 |
Jan
(2) |
Feb
|
Mar
(1) |
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
(1) |
Nov
|
Dec
|
2024 |
Jan
|
Feb
(3) |
Mar
|
Apr
(1) |
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
2025 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
(1) |
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
From: sandun c. <san...@gm...> - 2013-09-05 15:49:21
|
Thanks Brian for the response. I am using the sleuthkit sharp to read the file. There is no any compilation error. But, at run time, it seems tsk_fs_open_img() doesn't return the correct file info. (handle == IntPtr.Zero) But it reads img and iso files correctly. What could be the problem? On Thu, Sep 5, 2013 at 8:08 PM, Brian Carrier <ca...@sl...> wrote: > What error are you getting? Are you having trouble compiling or running? > Do you need the framework or did you really want TSK core? > > On Sep 5, 2013, at 10:17 AM, sandun css <san...@gm...> wrote: > > > Hi, > > > > I am new to TSK and Libewf and tried to use following (latest) TSK, > Libewf and Zlib versions together to process E01 files. > > > > sleuthkit-framework-win32-4.1.0 > > libewf-20130416 > > zlib-128 > > > > But it doesn't seem to be working. Can you please advice me on the > recommended compatible versions of these? > > > > Please note that I built libewf myself (didn't build TSK) to use it in > the sleuthkit sharp > > > > Thanks, > > Nilanga > > > ------------------------------------------------------------------------------ > > Learn the latest--Visual Studio 2012, SharePoint 2013, SQL 2012, more! > > Discover the easy way to master current and previous Microsoft > technologies > > and advance your career. Get an incredible 1,500+ hours of step-by-step > > tutorial videos with LearnDevNow. Subscribe today and save! > > > http://pubads.g.doubleclick.net/gampad/clk?id=58041391&iu=/4140/ostg.clktrk_______________________________________________ > > sleuthkit-users mailing list > > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > > http://www.sleuthkit.org > > |
From: Brian C. <ca...@sl...> - 2013-09-05 14:39:55
|
Agreed on the intended behavior. I'll log a bug about that. On Sep 5, 2013, at 9:16 AM, Grundy Barry J TIGTA <Bar...@ti...> wrote: > ./icat -f ext4 -r /dev/sda3 483647 >picture.jpg > > for any deleted file when I run an icat command like this I'm getting this error message > > Invalid API argument (tsk_fs_attrlist_get: Null list pointer) > > > > I don’t think I would label that as a bug…I’ve been testing 4.1.0 and what you are seeing is on my list of items to address (you beat me to it). > > I think the message is simply describing “expected behavior” for ext4, but it’s presenting itself as an error which seems a little confusing - at least that’s my take on it. The message is most likely coming from the fact that the Direct Blocks are zero’d out when a file is deleted on ext4 (as with ext3). If you run istat on the inode in question, you get the same error right where “direct blocks” are listed at the bottom of the output > > You won’t be able to recover deleted files on ext3/4 with icat. The block pointers are gone, and the error message is telling you that. It’s the “Error reading file:” that makes it look like a bug. > > You will get the same results with an ext3 image, but WITHOUT the confusing error message. The blocks just show up as empty in istat. > > I prefer the ext3 behavior. It might be nice to have both ext3 and ext4 state that there are no pointers to follow, to eliminate confusion. I would try a patch myself, but I’m no programmer. > > > /******************************************* > Barry J. Grundy > Assistant Special Agent in Charge > Digital Forensic Support Group > Electronic Crimes and Intelligence Division > Treasury Inspector General for Tax Administration > (301) 210-8741 (w) > (202) 527-5778 (c) > Bar...@ti... > ********************************************\ > > From: Maikel Alonso [mailto:mai...@gm...] > Sent: Thursday, September 05, 2013 8:09 AM > To: sle...@li... > Subject: [sleuthkit-users] Bug in the icat command into sleuthkit-4.1.0 version for EXT4 support > > Hi all: > > I'm testing the 4.1.0 version of sleuthkit and I think I've found a bug. > > I've compiled the sources downloaded from > > http://sourceforge.net/projects/sleuthkit/files/sleuthkit/4.1.0/sleuthkit-4.1.0.tar.gz/download > > and then when I use the command > > # fls -f ext4 -dpFrl /dev/sda3 on my Ubuntu 13.04 64bits > > > > I get correctly many line with information about deleted files > > all lines are like > > r/r * 483647: home/mainu/Imágenes/IMG_ > 20121114_190334.jpg 2013-09-05 07:12:50 (CEST) 2013-09-03 23:05:13 (CEST) 2013-09-05 07:12:50 (CEST) 2012-11-19 16:16:30 (CET) 0 1000 1000 > > but problem is when I run the command > > ./icat -f ext4 -r /dev/sda3 483647 >picture.jpg > > for any deleted file when I run an icat command like this I'm getting this error message > > Invalid API argument (tsk_fs_attrlist_get: Null list pointer) > > and nothing is recovered. > > This is not happening for fat deleted files. They are recovered correctly. > > Is there a bug in the ext4 support? What do you think? > > Thanks in advance. > Makelen > ------------------------------------------------------------------------------ > Learn the latest--Visual Studio 2012, SharePoint 2013, SQL 2012, more! > Discover the easy way to master current and previous Microsoft technologies > and advance your career. Get an incredible 1,500+ hours of step-by-step > tutorial videos with LearnDevNow. Subscribe today and save! > http://pubads.g.doubleclick.net/gampad/clk?id=58041391&iu=/4140/ostg.clktrk_______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org |
From: Brian C. <ca...@sl...> - 2013-09-05 14:38:59
|
What error are you getting? Are you having trouble compiling or running? Do you need the framework or did you really want TSK core? On Sep 5, 2013, at 10:17 AM, sandun css <san...@gm...> wrote: > Hi, > > I am new to TSK and Libewf and tried to use following (latest) TSK, Libewf and Zlib versions together to process E01 files. > > sleuthkit-framework-win32-4.1.0 > libewf-20130416 > zlib-128 > > But it doesn't seem to be working. Can you please advice me on the recommended compatible versions of these? > > Please note that I built libewf myself (didn't build TSK) to use it in the sleuthkit sharp > > Thanks, > Nilanga > ------------------------------------------------------------------------------ > Learn the latest--Visual Studio 2012, SharePoint 2013, SQL 2012, more! > Discover the easy way to master current and previous Microsoft technologies > and advance your career. Get an incredible 1,500+ hours of step-by-step > tutorial videos with LearnDevNow. Subscribe today and save! > http://pubads.g.doubleclick.net/gampad/clk?id=58041391&iu=/4140/ostg.clktrk_______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org |
From: sandun c. <san...@gm...> - 2013-09-05 14:17:23
|
Hi, I am new to TSK and Libewf and tried to use following (latest) TSK, Libewf and Zlib versions together to process E01 files. sleuthkit-framework-win32-4.1.0 libewf-20130416 zlib-128 But it doesn't seem to be working. Can you please advice me on the recommended compatible versions of these? Please note that I built libewf myself (didn't build TSK) to use it in the sleuthkit sharp Thanks, Nilanga |
From: sandun c. <san...@gm...> - 2013-09-05 14:16:42
|
Hi, I am new to TSK and Libewf and tried to use following (latest) TSK, Libewf and Zlib versions together to process E01 files. sleuthkit-framework-win32-4.1.0 libewf-20130416 zlib-128 But it doesn't seem to be working. Can you please advice me on the recommended compatible versions of these? Please note that I built libewf myself (didn't build TSK) to use it in the sleuthkit sharp Thanks, Nilanga |
From: Grundy B. J T. <Bar...@ti...> - 2013-09-05 13:16:59
|
./icat -f ext4 -r /dev/sda3 483647 >picture.jpg for any deleted file when I run an icat command like this I'm getting this error message Invalid API argument (tsk_fs_attrlist_get: Null list pointer) I don't think I would label that as a bug...I've been testing 4.1.0 and what you are seeing is on my list of items to address (you beat me to it). I think the message is simply describing "expected behavior" for ext4, but it's presenting itself as an error which seems a little confusing - at least that's my take on it. The message is most likely coming from the fact that the Direct Blocks are zero'd out when a file is deleted on ext4 (as with ext3). If you run istat on the inode in question, you get the same error right where "direct blocks" are listed at the bottom of the output You won't be able to recover deleted files on ext3/4 with icat. The block pointers are gone, and the error message is telling you that. It's the "Error reading file:" that makes it look like a bug. You will get the same results with an ext3 image, but WITHOUT the confusing error message. The blocks just show up as empty in istat. I prefer the ext3 behavior. It might be nice to have both ext3 and ext4 state that there are no pointers to follow, to eliminate confusion. I would try a patch myself, but I'm no programmer. /******************************************* Barry J. Grundy Assistant Special Agent in Charge Digital Forensic Support Group Electronic Crimes and Intelligence Division Treasury Inspector General for Tax Administration (301) 210-8741 (w) (202) 527-5778 (c) Bar...@ti... ********************************************\ From: Maikel Alonso [mailto:mai...@gm...] Sent: Thursday, September 05, 2013 8:09 AM To: sle...@li... Subject: [sleuthkit-users] Bug in the icat command into sleuthkit-4.1.0 version for EXT4 support Hi all: I'm testing the 4.1.0 version of sleuthkit and I think I've found a bug. I've compiled the sources downloaded from http://sourceforge.net/projects/sleuthkit/files/sleuthkit/4.1.0/sleuthkit-4.1.0.tar.gz/download and then when I use the command # fls -f ext4 -dpFrl /dev/sda3 on my Ubuntu 13.04 64bits I get correctly many line with information about deleted files all lines are like r/r * 483647: home/mainu/Imágenes/IMG_ 20121114_190334.jpg 2013-09-05 07:12:50 (CEST) 2013-09-03 23:05:13 (CEST) 2013-09-05 07:12:50 (CEST) 2012-11-19 16:16:30 (CET) 0 1000 1000 but problem is when I run the command ./icat -f ext4 -r /dev/sda3 483647 >picture.jpg for any deleted file when I run an icat command like this I'm getting this error message Invalid API argument (tsk_fs_attrlist_get: Null list pointer) and nothing is recovered. This is not happening for fat deleted files. They are recovered correctly. Is there a bug in the ext4 support? What do you think? Thanks in advance. Makelen |
From: Maikel A. <mai...@gm...> - 2013-09-05 12:08:40
|
Hi all: I'm testing the 4.1.0 version of sleuthkit and I think I've found a bug. I've compiled the sources downloaded from http://sourceforge.net/projects/sleuthkit/files/sleuthkit/4.1.0/sleuthkit-4.1.0.tar.gz/download and then when I use the command # fls -f ext4 -dpFrl /dev/sda3 on my Ubuntu 13.04 64bits I get correctly many line with information about deleted files all lines are like r/r * 483647: home/mainu/Imágenes/IMG_ 20121114_190334.jpg 2013-09-05 07:12:50 (CEST) 2013-09-03 23:05:13 (CEST) 2013-09-05 07:12:50 (CEST) 2012-11-19 16:16:30 (CET) 0 1000 1000 but problem is when I run the command ./icat -f ext4 -r /dev/sda3 483647 >picture.jpg for any deleted file when I run an icat command like this I'm getting this error message Invalid API argument (tsk_fs_attrlist_get: Null list pointer) and nothing is recovered. This is not happening for fat deleted files. They are recovered correctly. Is there a bug in the ext4 support? What do you think? Thanks in advance. Makelen |
From: Joachim M. <joa...@gm...> - 2013-09-05 08:35:54
|
Brian thanks for accepting the patches. On Fri, Aug 30, 2013 at 7:22 AM, Joachim Metz <joa...@gm...>wrote: > I've also added a fix for a memory leak in the yaffs code for the error > code path. I'm wondering though if a particular member of the yaffs > internal structure chunkMap is freed in the normal code path? > I've not tested it yet with a yaffs test image, but if you do please run a > tool like valgrind on the tsk tools i.c.w. the yaffs test image. > > > On Thu, Aug 29, 2013 at 7:23 AM, Joachim Metz <joa...@gm...>wrote: > >> > I haven't tracked the final number. Is that set by the libtool/LDFLAGS >> version? >> >> This is controlled by: >> libtsk_la_LDFLAGS = -version-info 10:0:0 >> >> in: tsk/Makefile.am >> >> > It looks good. I'll review it later today and merge it in. >> Thanks, but please revisit the code in this file I did not touch. >> >> Also seeing the compiler warnings I expect there are signed/unsigned >> issues in various more places. >> >> > I see Jeff every day at work. We're waiting to merge that in, but >> will probably do it by end of week. In hindsight, we should probably have >> made a 64-bit branch instead. >> >> Can you maybe add something to the develop guidelines about what to >> expect and which email address to ping for more urgent patches? >> >> http://wiki.sleuthkit.org/index.php?title=Developer_Guidelines >> >> >> >> >> >> On Thu, Aug 29, 2013 at 5:07 AM, Brian Carrier <ca...@sl...>wrote: >> >>> Hey Joachim, >>> >>> On Aug 28, 2013, at 4:57 PM, Joachim Metz wrote: >>> >>> > So I've just add a pull request to github, can anyone tell me what to >>> expect on the response side? >>> >>> It looks good. I'll review it later today and merge it in. >>> >>> > I see one other recent pull request of 14 days ago where it seems no >>> one from the project has replied. >>> >>> I see Jeff every day at work. We're waiting to merge that in, but will >>> probably do it by end of week. In hindsight, we should probably have made a >>> 64-bit branch instead. >>> >>> > Note that this pull request is supposed to fix a serious defect >>> causing the current code to segfault. Also at first glance this file needs >>> some serious revisiting. >>> > >>> > >>> > Also what's up with the current so version number, why did it jump >>> from 3 to 9 to 10 !? Also because the API is largely untouched? >>> > >>> > sleuthkit 3.x.x was soname libtsk3.3 >>> > sleuthkit 4.0.0 was soname libtsk3.3 >>> > sleuthkit 4.0.1 was soname libtsk3.9 >>> > sleuthkit 4.0.2 was soname libtsk3.9 >>> > sleuthkit 4.1.0 was soname libtsk.10 >>> >>> I haven't tracked the final number. Is that set by the libtool/LDFLAGS >>> version? >>> >>> > Also can someone elaborate on the sudden change of hart to rename >>> libtsk3 into libtsk? >>> >>> Because TSK has been version 4 for almost a year and the '3' was for >>> version 3. I dropped the version from the library name (and include paths). >>> >>> brian >>> >>> >>> >> > |
From: Netexpress <Net...@ti...> - 2013-09-04 21:25:37
|
Hi Brian, thanks very much for your help. I fill your tips with more data. > > 3- If i go on view three and select deleted files all seems to be freeze, > and even if I know that are present many deleted files i do not find noone of > them. > > Meaning that the entire system freezes? I haven't seen that yet, but can > certainly make some test images to stress that feature. If you select "Deleted > Files", it should show two child entries (File System and All). What are the > numbers next to those? Let me explain more about my lab of analysis I have autopy on Windows 2003 virtual machine with 4GB Ram and 2 Processor. I am using vmware server 2.0 running on linux; and I connect to windows 2003 to use autopsy with terminal server using administator user; a bit complitated scenario? :-) The image on witch I am working is on original image of 36GB that police have duplicated to lawyer on 500GB disk via dd or logicube, not a dd raw image file but dd output on disk device of 500 GB, and when I made raw image from this disk I get an image of 500GB, the one on witch I am working. Something mistake in the process? Now I will try to explai more about the problem The system is ok i notice a fixed use of 50% of cpu from autopsy. everyhing I choose on menu and view of autopsy is too slow and many times i cannot change view. Furthermore if I iconize autopys it doesnt return to full windows. If I try to kill processi t goes on state "not responding" On deleted files view autopsy report: File System 883162 All 883162 But I am not able to vew the list of files Looking into event viewer I have found this, only one occurence, if can help Application: Event Type: Error Event Source: Application Hang Event Category: (101) Event ID: 1002 Date: 28/08/2013 Time: 23.30.36 User: N/A Computer: LABORATORIO Description: Hanging application autopsy.exe, version 0.0.0.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000. For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp. Data: 0000: 41 70 70 6c 69 63 61 74 Applicat 0008: 69 6f 6e 20 48 61 6e 67 ion Hang 0010: 20 20 61 75 74 6f 70 73 autops 0018: 79 2e 65 78 65 20 30 2e y.exe 0. 0020: 30 2e 30 2e 30 20 69 6e 0.0.0 in 0028: 20 68 75 6e 67 61 70 70 hungapp 0030: 20 30 2e 30 2e 30 2e 30 0.0.0.0 0038: 20 61 74 20 6f 66 66 73 at offs 0040: 65 74 20 30 30 30 30 30 et 00000 0048: 30 30 30 000 I have used autopy 2 on linux and found this new versioni very good more intuitive and better for general view of the case. The only two things could be of help, for me, should be a log of what is doing with a marker of activity, and a dialog box telling to wait for process to complete, sometimes the user things that all was completed even if it's going on. Sorry for my bad english, and thanks very much for your help. Alessandro Fiorenzi |
From: Umit K. <umi...@gm...> - 2013-09-04 19:34:08
|
Hi Ade, Thanks for your response. It helps me to understand the nature of tsk_recover. And, yes I'm testing photorec as well. Thanks for your help again. Umit -- View this message in context: http://filesystems.996266.n3.nabble.com/tsk-recover-tool-configuration-tp8156p8158.html Sent from the sleuthkit-users mailing list archive at Nabble.com. |
From: Ade <adr...@nt...> - 2013-09-04 19:28:46
|
Hi Umit Strictly speaking, tsk_recover is not a file carving tool (assuming one defines file carving as the searching and recovery of files based on file signature). It is a file undeletion tool - one that recovers files based on meta-data in the inode table/MFT/FAT. You can run tsk_recover then filter the recovered files based on file signature analysis and/or file extension analysis. AFAIK, tsk_recover doesn't look at the file headers, thus there is no way to customise it to search for file types in the way you can with scalpel/foremost. I think Brian is looking at integrating file carving tools, in the meantime have you looked at photorec? Ade On Wednesday 04 Sep 2013 12:20:13 Umit Karabiyik wrote: > Hello all, > > I am working on data carving. I found that it's easy to configure > scalpel/foremost to search for specific file type. However, man page for > tsk_recover doesn't mention any configuration file. It seems to me that > tsk_recover all type of files and no option can be specified by the user. Is > that correct? If not, how can I configure tsk_recover in order to carve out > specific type of files such as .txt files only. > > Thanks in advance, > Umit > > > > -- > View this message in context: > http://filesystems.996266.n3.nabble.com/tsk-recover-tool-configuration-tp81 > 56.html Sent from the sleuthkit-users mailing list archive at Nabble.com. > > ---------------------------------------------------------------------------- > -- Learn the latest--Visual Studio 2012, SharePoint 2013, SQL 2012, more! > Discover the easy way to master current and previous Microsoft technologies > and advance your career. Get an incredible 1,500+ hours of step-by-step > tutorial videos with LearnDevNow. Subscribe today and save! > http://pubads.g.doubleclick.net/gampad/clk?id=58040911&iu=/4140/ostg.clktrk > _______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org |
From: Umit K. <umi...@gm...> - 2013-09-04 19:20:20
|
Hello all, I am working on data carving. I found that it's easy to configure scalpel/foremost to search for specific file type. However, man page for tsk_recover doesn't mention any configuration file. It seems to me that tsk_recover all type of files and no option can be specified by the user. Is that correct? If not, how can I configure tsk_recover in order to carve out specific type of files such as .txt files only. Thanks in advance, Umit -- View this message in context: http://filesystems.996266.n3.nabble.com/tsk-recover-tool-configuration-tp8156.html Sent from the sleuthkit-users mailing list archive at Nabble.com. |
From: Brian C. <ca...@sl...> - 2013-09-04 15:26:13
|
On Sep 4, 2013, at 6:58 AM, Brian Carrier <ca...@sl...> wrote: > > On Sep 3, 2013, at 5:12 PM, Netexpress <Net...@ti...> wrote: > >> 2- If I use keyword search on top on right I get this message: “No files are indexed, please index an image before searching” who can i do? > > Was the Keyword Search ingest module enabled when you added the disk image. It is responsible for adding files to the index. If it was enabled, you may need to wait (I'll review that message to see if it can be made more clear). The currently released version of Autopsy "commits" its index every 10 minutes while ingest is occurring. The faster you commit, the longer the ingest takes. The next version changes that value to 5 minutes. That means that for 10 minutes, new files will not be visible to you in the index. I think we updated the message to be more clear about why there are no results, but I'll double check. I just updated the message to be more detailed if the search is conducted when ingest is ongoing and there are no files. |
From: Brian C. <ca...@sl...> - 2013-09-04 13:00:20
|
On Sep 3, 2013, at 5:12 PM, Netexpress <Net...@ti...> wrote: > Hi, > I am new of autopsy,. I am using autopsy 3.0.6 on windows 2003 and on win 7. Sounds good. For future reference for everyone, there is a quick start guide on the web: http://sleuthkit.org/autopsy/docs/quick/ > I create a case, insert keyword to search and run ingest modules on data source. And now the problems: > 1- I get a message on bottom “no known bad database set” ; where and how to set it? 2 ways. - If you are adding a disk image / data source, choose the Hash Lookup module when you get the list of ingest modules and then choose "Advanced". It will allow you to import NSRL databases (which you can download from https://sourceforge.net/projects/autopsy/files/NSRL/) of 'known' files that will be ignored by other ingest modules or you can add a database of 'known bad'. We don't distribute 'known bad' databases. We support EnCase, Hashkeeper, and md5sum formats. - From within the tool, you can choose the Tools menu and then Options -> Hash Database and get to the same panel. > 2- If I use keyword search on top on right I get this message: “No files are indexed, please index an image before searching” who can i do? Was the Keyword Search ingest module enabled when you added the disk image. It is responsible for adding files to the index. If it was enabled, you may need to wait (I'll review that message to see if it can be made more clear). The currently released version of Autopsy "commits" its index every 10 minutes while ingest is occurring. The faster you commit, the longer the ingest takes. The next version changes that value to 5 minutes. That means that for 10 minutes, new files will not be visible to you in the index. I think we updated the message to be more clear about why there are no results, but I'll double check. > 3- If i go on view three and select deleted files all seems to be freeze, and even if I know that are present many deleted files i do not find noone of them. Meaning that the entire system freezes? I haven't seen that yet, but can certainly make some test images to stress that feature. If you select "Deleted Files", it should show two child entries (File System and All). What are the numbers next to those? > Perhaps I am newbie of autopsy, and my question cuold seems to be stupid but are many days I try and try to understand and solve it. > > Last question, can someone suggest a good tutorial for autopsy3 realistic use ? We haven't built one yet besides the other docs. Sorry. Perhaps someone else can ... :) thanks, brian |
From: Netexpress <Net...@ti...> - 2013-09-03 21:12:44
|
Hi, I am new of autopsy,. I am using autopsy 3.0.6 on windows 2003 and on win 7. I create a case, insert keyword to search and run ingest modules on data source. And now the problems: 1- I get a message on bottom "no known bad database set" ; where and how to set it? 2- If I use keyword search on top on right I get this message: "No files are indexed, please index an image before searching" who can i do? 3- If i go on view three and select deleted files all seems to be freeze, and even if I know that are present many deleted files i do not find noone of them. Perhaps I am newbie of autopsy, and my question cuold seems to be stupid but are many days I try and try to understand and solve it. Last question, can someone suggest a good tutorial for autopsy3 realistic use ? NetExpress |
From: Greg F. <gre...@gm...> - 2013-09-02 14:49:05
|
Matt, If you happen to have X-Ways, this video is very informative and shows you how to easily generate a timeline such as you wanted: https://www.youtube.com/watch?v=867FQrKhhFM&feature=c4-overview&list=UUCZZotqcuThvBzCeb_KYhpw For all: can FTK or EnCase do this sort of thing yet? I haven't kept up with their feature sets and X-Ways just got event list processing about 6 months ago. (Yes, I know log2timeline (and soon to be plaso) has been able to do similar things for a few years now.) Greg Greg -- Greg Freemyer On Fri, Aug 30, 2013 at 3:44 PM, MATT PIERCE <mat...@ad...> wrote: > I’m working with an image and trying to create a timeline of user login’s. > At a minimum I would like to show the last several logins and their > time/date of logging in. I can check out the date stamps for their profile > but that would just show the last time that particular login occurred. Can > anyway I can generate a timeline of the last 10 or so login events? The > system was not in my possession nor connected to my domain when the login > activity occurred. > > > ------------------------------------------------------------------------------ > Learn the latest--Visual Studio 2012, SharePoint 2013, SQL 2012, more! > Discover the easy way to master current and previous Microsoft technologies > and advance your career. Get an incredible 1,500+ hours of step-by-step > tutorial videos with LearnDevNow. Subscribe today and save! > http://pubads.g.doubleclick.net/gampad/clk?id=58040911&iu=/4140/ostg.clktrk > _______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org > |
From: MATT P. <mat...@ad...> - 2013-08-30 22:14:40
|
Thank you all for your info. I’ve been working on pulling the Eventlogs, and I’m looking for correlating details. The image I have was taken after the machine was handed to me long after the supposed events. I’m looking for several lines of dating login events to see if they all hang together. From: MATT PIERCE Sent: Friday, August 30, 2013 5:12 PM To: 'Joachim Metz' Subject: RE: Determining User Login Activity I’m not sure about the service pack version. I’ll follow up on that. It was a desktop PC that was running local off site. The default policy for windows is to keep the cached credentials for the last 10 users. I’m thinking that the registry key might have useful timestamps. The values should be stored in HKEY_LOCAL_MACHINE\Security\Cache but I haven’t located them in the image. Thanks for the suggestions. From: Joachim Metz [mailto:joa...@gm...] Sent: Friday, August 30, 2013 4:23 PM To: MATT PIERCE Subject: Re: Determining User Login Activity > which version of XP there are significant differences between the service packs > I recall that the OS keeps the last 10 logins in the registry, 10 logons of what? a single user or the last per user? local or domain logons? RDP logons? > the default GPO keeps the last 10 password hashes are you referring to the cached credentials? or the local accounts? Also what particular group policy setting are you referring to? 1. Start with the event logs. Check if they contain logon/logoff events. 2. Check the SAM registry file Is the system a laptop or a desktop? In case it's a single user machine you might piece together the approximate logons from system activity. On Fri, Aug 30, 2013 at 11:05 PM, MATT PIERCE <mat...@ad...<mailto:mat...@ad...>> wrote: It’s a dd of the disk for a windows xp system. I recall that the OS keeps the last 10 logins in the registry, or at least the default GPO keeps the last 10 password hashes. I think that key may have the information I’m looking for if I can work out where that key is. From: Joachim Metz [mailto:joa...@gm...<mailto:joa...@gm...>] Sent: Friday, August 30, 2013 4:00 PM To: MATT PIERCE Subject: Re: Determining User Login Activity Matt, what type of image? Image of what system? workstation/server? (from your comment I assume workstation) what OS? version? (from the profile and domain comment I assume Windows) > Can anyway I can generate a timeline of the last 10 or so login events? Maybe; what's in the Windows event logs? any log-on events? what is the config? on Windows do you have logon/logoff auditing turned on? (check the registry for this) Is a logon required in the first place? Are the profiles roaming? or local? On Fri, Aug 30, 2013 at 9:42 PM, MATT PIERCE <mat...@ad...<mailto:mat...@ad...>> wrote: I’m working with an image and trying to create a timeline of user login’s. Or at a minimum show the last several logins and their time/date of logging in. I can check out the date stamps for their profile but that would just show the last time that particular login occurred. Can anyway I can generate a timeline of the last 10 or so login events? The system was not in my possession nor connected to my domain when the login activity occurred. |
From: Greg F. <gre...@gm...> - 2013-08-30 20:51:34
|
If it's a workgroup situation there should be login/logoff events in the security event log. But be advised a lot of users never logoff. I just reviewed in detail 2 weeks of events on a case. I don't recall any logon events in there (but I wasn't looking for them either). >From my own PC in a workgroup, this is the last login event OF MINE in the security logs (lots of virtual logins by SYSTEM account I had to ignore to find this one). I redacted some of the fields: Subject: Security ID: SYSTEM Account Name: XXXXXXXXXX$ Account Domain: XXX Logon ID: 0x3e7 Logon Type: 7 New Logon: Security ID: XXXXXXXXXX\GAF Account Name: GAF Account Domain: XXXXXXXXXX Logon ID: 0x2916d72 Logon GUID: {00000000-0000-0000-0000-000000000000} Note that my login ID is listed and the logon type was 7 (7 means I was at the keyboard, not remote). Greg Greg -- Greg Freemyer On Fri, Aug 30, 2013 at 3:44 PM, MATT PIERCE <mat...@ad...> wrote: > I’m working with an image and trying to create a timeline of user login’s. > At a minimum I would like to show the last several logins and their > time/date of logging in. I can check out the date stamps for their profile > but that would just show the last time that particular login occurred. Can > anyway I can generate a timeline of the last 10 or so login events? The > system was not in my possession nor connected to my domain when the login > activity occurred. > > > ------------------------------------------------------------------------------ > Learn the latest--Visual Studio 2012, SharePoint 2013, SQL 2012, more! > Discover the easy way to master current and previous Microsoft technologies > and advance your career. Get an incredible 1,500+ hours of step-by-step > tutorial videos with LearnDevNow. Subscribe today and save! > http://pubads.g.doubleclick.net/gampad/clk?id=58040911&iu=/4140/ostg.clktrk > _______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org > |
From: <slo...@gm...> - 2013-08-30 20:47:36
|
The windows event logs record user logins. Log2timeline ( http://log2timeline.net/) creates timelines that include event log content, but I don't recall if logins are included. If not, grokevt ( http://projects.sentinelchicken.org/grokevt/) might automate event log parsing for you. On Fri, Aug 30, 2013 at 12:44 PM, MATT PIERCE <mat...@ad...>wrote: > I’m working with an image and trying to create a timeline of user > login’s. At a minimum I would like to show the last several logins and > their time/date of logging in. I can check out the date stamps for their > profile but that would just show the last time that particular login > occurred. Can anyway I can generate a timeline of the last 10 or so > login events? The system was not in my possession nor connected to my > domain when the login activity occurred. **** > > > ------------------------------------------------------------------------------ > Learn the latest--Visual Studio 2012, SharePoint 2013, SQL 2012, more! > Discover the easy way to master current and previous Microsoft technologies > and advance your career. Get an incredible 1,500+ hours of step-by-step > tutorial videos with LearnDevNow. Subscribe today and save! > http://pubads.g.doubleclick.net/gampad/clk?id=58040911&iu=/4140/ostg.clktrk > _______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org > > |
From: bolo d. <bol...@gm...> - 2013-08-30 20:45:38
|
My approach would be along the lines of: 1. start with the registries and use RegRipper for last login - https://code.google.com/p/regripper 2. then move into the Windows Security event log, I think the logon IDs to search for would 528/4624 depending on the version of Windows (can anyone else confirm?) - in Windows 7 - /Windows/System32/winevt/Logs/Security.evtx TZWorks does a good Event Log viewer (other viewers/parsers exist too). 3. then for more timestamps the user's Shell bags would be good to help get a feel for user activity during logins. TZWorks do an excellent tool called sbag. Run against UsrClass.dat or NTUSER.dat depending on the windows version (e.g. XP - NTUSER, Vista+ Usrclass). Ideally a more complete user/system timeline should be created with log2timeline (code.google.com/p/plaso/), that would provide better context of machine and user activity. Hope that helps bd On Fri, Aug 30, 2013 at 8:44 PM, MATT PIERCE <mat...@ad...> wrote: > I’m working with an image and trying to create a timeline of user > login’s. At a minimum I would like to show the last several logins and > their time/date of logging in. I can check out the date stamps for their > profile but that would just show the last time that particular login > occurred. Can anyway I can generate a timeline of the last 10 or so > login events? The system was not in my possession nor connected to my > domain when the login activity occurred. **** > > > ------------------------------------------------------------------------------ > Learn the latest--Visual Studio 2012, SharePoint 2013, SQL 2012, more! > Discover the easy way to master current and previous Microsoft technologies > and advance your career. Get an incredible 1,500+ hours of step-by-step > tutorial videos with LearnDevNow. Subscribe today and save! > http://pubads.g.doubleclick.net/gampad/clk?id=58040911&iu=/4140/ostg.clktrk > _______________________________________________ > sleuthkit-users mailing list > https://lists.sourceforge.net/lists/listinfo/sleuthkit-users > http://www.sleuthkit.org > > |
From: MATT P. <mat...@ad...> - 2013-08-30 20:01:43
|
I’m working with an image and trying to create a timeline of user login’s. At a minimum I would like to show the last several logins and their time/date of logging in. I can check out the date stamps for their profile but that would just show the last time that particular login occurred. Can anyway I can generate a timeline of the last 10 or so login events? The system was not in my possession nor connected to my domain when the login activity occurred. |
From: Joachim M. <joa...@gm...> - 2013-08-30 05:23:05
|
I've also added a fix for a memory leak in the yaffs code for the error code path. I'm wondering though if a particular member of the yaffs internal structure chunkMap is freed in the normal code path? I've not tested it yet with a yaffs test image, but if you do please run a tool like valgrind on the tsk tools i.c.w. the yaffs test image. On Thu, Aug 29, 2013 at 7:23 AM, Joachim Metz <joa...@gm...>wrote: > > I haven't tracked the final number. Is that set by the libtool/LDFLAGS > version? > > This is controlled by: > libtsk_la_LDFLAGS = -version-info 10:0:0 > > in: tsk/Makefile.am > > > It looks good. I'll review it later today and merge it in. > Thanks, but please revisit the code in this file I did not touch. > > Also seeing the compiler warnings I expect there are signed/unsigned > issues in various more places. > > > I see Jeff every day at work. We're waiting to merge that in, but will > probably do it by end of week. In hindsight, we should probably have made a > 64-bit branch instead. > > Can you maybe add something to the develop guidelines about what to expect > and which email address to ping for more urgent patches? > > http://wiki.sleuthkit.org/index.php?title=Developer_Guidelines > > > > > > On Thu, Aug 29, 2013 at 5:07 AM, Brian Carrier <ca...@sl...>wrote: > >> Hey Joachim, >> >> On Aug 28, 2013, at 4:57 PM, Joachim Metz wrote: >> >> > So I've just add a pull request to github, can anyone tell me what to >> expect on the response side? >> >> It looks good. I'll review it later today and merge it in. >> >> > I see one other recent pull request of 14 days ago where it seems no >> one from the project has replied. >> >> I see Jeff every day at work. We're waiting to merge that in, but will >> probably do it by end of week. In hindsight, we should probably have made a >> 64-bit branch instead. >> >> > Note that this pull request is supposed to fix a serious defect causing >> the current code to segfault. Also at first glance this file needs some >> serious revisiting. >> > >> > >> > Also what's up with the current so version number, why did it jump from >> 3 to 9 to 10 !? Also because the API is largely untouched? >> > >> > sleuthkit 3.x.x was soname libtsk3.3 >> > sleuthkit 4.0.0 was soname libtsk3.3 >> > sleuthkit 4.0.1 was soname libtsk3.9 >> > sleuthkit 4.0.2 was soname libtsk3.9 >> > sleuthkit 4.1.0 was soname libtsk.10 >> >> I haven't tracked the final number. Is that set by the libtool/LDFLAGS >> version? >> >> > Also can someone elaborate on the sudden change of hart to rename >> libtsk3 into libtsk? >> >> Because TSK has been version 4 for almost a year and the '3' was for >> version 3. I dropped the version from the library name (and include paths). >> >> brian >> >> >> > |
From: Joachim M. <joa...@gm...> - 2013-08-29 05:23:38
|
> I haven't tracked the final number. Is that set by the libtool/LDFLAGS version? This is controlled by: libtsk_la_LDFLAGS = -version-info 10:0:0 in: tsk/Makefile.am > It looks good. I'll review it later today and merge it in. Thanks, but please revisit the code in this file I did not touch. Also seeing the compiler warnings I expect there are signed/unsigned issues in various more places. > I see Jeff every day at work. We're waiting to merge that in, but will probably do it by end of week. In hindsight, we should probably have made a 64-bit branch instead. Can you maybe add something to the develop guidelines about what to expect and which email address to ping for more urgent patches? http://wiki.sleuthkit.org/index.php?title=Developer_Guidelines On Thu, Aug 29, 2013 at 5:07 AM, Brian Carrier <ca...@sl...>wrote: > Hey Joachim, > > On Aug 28, 2013, at 4:57 PM, Joachim Metz wrote: > > > So I've just add a pull request to github, can anyone tell me what to > expect on the response side? > > It looks good. I'll review it later today and merge it in. > > > I see one other recent pull request of 14 days ago where it seems no one > from the project has replied. > > I see Jeff every day at work. We're waiting to merge that in, but will > probably do it by end of week. In hindsight, we should probably have made a > 64-bit branch instead. > > > Note that this pull request is supposed to fix a serious defect causing > the current code to segfault. Also at first glance this file needs some > serious revisiting. > > > > > > Also what's up with the current so version number, why did it jump from > 3 to 9 to 10 !? Also because the API is largely untouched? > > > > sleuthkit 3.x.x was soname libtsk3.3 > > sleuthkit 4.0.0 was soname libtsk3.3 > > sleuthkit 4.0.1 was soname libtsk3.9 > > sleuthkit 4.0.2 was soname libtsk3.9 > > sleuthkit 4.1.0 was soname libtsk.10 > > I haven't tracked the final number. Is that set by the libtool/LDFLAGS > version? > > > Also can someone elaborate on the sudden change of hart to rename > libtsk3 into libtsk? > > Because TSK has been version 4 for almost a year and the '3' was for > version 3. I dropped the version from the library name (and include paths). > > brian > > > |
From: Brian C. <ca...@sl...> - 2013-08-29 03:07:16
|
Hey Joachim, On Aug 28, 2013, at 4:57 PM, Joachim Metz wrote: > So I've just add a pull request to github, can anyone tell me what to expect on the response side? It looks good. I'll review it later today and merge it in. > I see one other recent pull request of 14 days ago where it seems no one from the project has replied. I see Jeff every day at work. We're waiting to merge that in, but will probably do it by end of week. In hindsight, we should probably have made a 64-bit branch instead. > Note that this pull request is supposed to fix a serious defect causing the current code to segfault. Also at first glance this file needs some serious revisiting. > > > Also what's up with the current so version number, why did it jump from 3 to 9 to 10 !? Also because the API is largely untouched? > > sleuthkit 3.x.x was soname libtsk3.3 > sleuthkit 4.0.0 was soname libtsk3.3 > sleuthkit 4.0.1 was soname libtsk3.9 > sleuthkit 4.0.2 was soname libtsk3.9 > sleuthkit 4.1.0 was soname libtsk.10 I haven't tracked the final number. Is that set by the libtool/LDFLAGS version? > Also can someone elaborate on the sudden change of hart to rename libtsk3 into libtsk? Because TSK has been version 4 for almost a year and the '3' was for version 3. I dropped the version from the library name (and include paths). brian |
From: Joachim M. <joa...@gm...> - 2013-08-28 20:58:07
|
So I've just add a pull request to github, can anyone tell me what to expect on the response side? I see one other recent pull request of 14 days ago where it seems no one from the project has replied. Note that this pull request is supposed to fix a serious defect causing the current code to segfault. Also at first glance this file needs some serious revisiting. Also what's up with the current so version number, why did it jump from 3 to 9 to 10 !? Also because the API is largely untouched? sleuthkit 3.x.x was soname libtsk3.3 sleuthkit 4.0.0 was soname libtsk3.3 sleuthkit 4.0.1 was soname libtsk3.9 sleuthkit 4.0.2 was soname libtsk3.9 sleuthkit 4.1.0 was soname libtsk.10 Also can someone elaborate on the sudden change of hart to rename libtsk3 into libtsk? |