Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Full Disclosure: Re: Forensic help?

Re: Forensic help?

From: <als_at_thangorodrim.de>
Date: Mon, 12 Sep 2005 17:02:04 +0200

On Mon, Sep 12, 2005 at 10:11:24AM -0400, Red Leg wrote:
> On 9/11/05 8:21 PM, "Paul Schmehl" <pauls_at_utdallas.edu> wrote:
>
>
> > Download the knoppix std distro and burn it to a cd. Use dcfldd for drive
> > imaging and the forensics tools for recovery of erased files and the like.
> >
>
> Paul.
>
> Does dcfldd allow me to mirror the disk in such a manner as to include
> deleted files? I can not swap drives. I need to obtain an image with which I
> can "undelete" files that were conventionally erased.
>
> Will dcfldd provide such an image?

I haven't used dcfldd, but it seems to be a modified version of the
standard UNIX tool dd. As such it should produce a block level image of
the disk - which includes everything on the disk, deleted or not.

Regards,
    Alex.

-- 
"Opportunity is missed by most people because it is dressed in overalls and
 looks like work."                                      -- Thomas A. Edison
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Received on Sep 12 2005
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]