Re: forensics tools - preserving data?

From: GuidoZ (uberguidoz_at_gmail.com)
Date: 10/05/04

  • Next message: Oscar Kooijman: "RE: forensics tools - preserving data?"
    Date: Tue, 5 Oct 2004 00:03:51 -0700
    To: Dana Rawson <absolutezero273c@nzoomail.com>
    
    

    There are a myraid of forensic tools out there free for the taking.
    Being I'm not fully versed in them all, I'll just toss up some links
    and let you decide which might work the best. =)

    PHLAK (Pro Hackers Linux Assult Kit)
     - http://www.phlak.org/

    Penguin Sleuth
     - http://www.linux-forensics.com/

    Knoppix-std (Security Tools Distrobution
     - http://www.knoppix-std.org/

    L.A.S. (Local Area Security)
     - http://www.localareasecurity.com/

    NST (Network Security Toolkit
     - http://www.networksecuritytoolkit.org/

    Those are my favs. I saved the best link for last however. Some quick
    "CTRL+F" searching on this page should prove to be quite useful...

    List of Live CDs (Linux, all types)
     - http://www.frozentech.com/content/livecd.php

    Best of luck in your quest. I've had quite a bit of luck with both
    Penguin Sleuth and PHLAK when it comes to data forensics. There was
    another one that I wish I could remember... it was posted to this
    list. It's bookmarked on a different system unfortunately.

    Finally, hopefully Harlan Carvey will pipe up and share his expertise.
    See http://www.windows-ir.com/ for more info.

    --
    Peace. ~G
    On 4 Oct 2004 17:44:06 -0000, Dana Rawson <absolutezero273c@nzoomail.com> wrote:
    > 
    > 
    > G'Day All,
    > 
    > Before I begin, I wanted to thank everyone who had provided me with direction on my last post regarding pgp.
    > 
    > Hopefully I have as simple a question as before.
    > 
    > I have a client who recently had to terminate an employee and part of their decision was based on dereliction of duty.  Basically too much time spent surfing the internet and not performing her expected duties.
    > 
    > They have asked me to gather the internet history, temporary internet directory files, etc.
    > 
    > I can pull up the files, archive them and explain the information to them.  But how do I go about extracting the information (i.e. The internet address of the many files that lie in the temp internet dir) so I am able to present it in acceptable fashion that they might use it in a court of law as evidence should it come to that.
    > 
    > I have been looking but can't seem to find what I think I need.  I have located tools on http://www.networkintrusion.co.uk/fortools.htm
    > 
    >  and see that NetAnalysis might prove useful but appears to be overkill.  Or is this exactly what I need?
    > 
    > Thanks in advance, again.
    >
    

  • Next message: Oscar Kooijman: "RE: forensics tools - preserving data?"

    Relevant Pages

    • [NT] Vulnerability in Microsoft Data Access Components Allows Code Execution (MS07-009)
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Get your security news from a reliable source. ... this vulnerability by preventing Active Scripting and ActiveX controls ... mode sets the security level for the Internet zone to High. ...
      (Securiteam)
    • Testimony of Jeff Schmidt, CEO, Authis
      ... Examining the Security Implications of Proposed Online Gambling Regulation ... recognized expert on issues related to online identification and authentication, ... authentication, and age verification. ... individual using The Internet. ...
      (rec.gambling.poker)
    • << SBS news of the week 12/6/2004>>
      ... Simply connecting to the Internet — and doing ... You would NEVER set up a server with file and printing sharing ports ... McAfee says 'Skulls' mobile security threat still low ... ISPs raise the stakes on DDoS attacks ...
      (microsoft.public.backoffice.smallbiz2000)
    • << SBS news of the week 12/6/2004>>
      ... Simply connecting to the Internet — and doing ... You would NEVER set up a server with file and printing sharing ports ... McAfee says 'Skulls' mobile security threat still low ... ISPs raise the stakes on DDoS attacks ...
      (microsoft.public.windows.server.sbs)
    • Hackers Shift to Financial Gain
      ... Internet criminals not content to just wreak havoc online ... The prime objective for hackers and online thieves has shifted from ... largely hitting major corporate networks to gaining control of home ... Symantec this week released its Internet Security Threat Report. ...
      (comp.dcom.telecom)

  • Quantcast