<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: The Sleutkit 2.06 and Autopsy 2.08</title>
	<atom:link href="http://geschonneck.com/2006/09/02/the-sleutkit-206-and-autopsy-208/feed/" rel="self" type="application/rss+xml" />
	<link>http://geschonneck.com/2006/09/02/the-sleutkit-206-and-autopsy-208/</link>
	<description>This is the private security page of Alexander Geschonneck (Berlin, Germany).</description>
	<pubDate>Tue, 06 Jan 2009 07:38:05 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.5</generator>
		<item>
		<title>By: anwer</title>
		<link>http://geschonneck.com/2006/09/02/the-sleutkit-206-and-autopsy-208/#comment-3175</link>
		<dc:creator>anwer</dc:creator>
		<pubDate>Wed, 03 Jan 2007 09:05:19 +0000</pubDate>
		<guid isPermaLink="false">http://geschonneck.com/2006/09/02/the-sleutkit-206-and-autopsy-208/#comment-3175</guid>
		<description>s both have the ame hash value! 
tried fsstat with the stick but it says "superblock read: is a directory"

however i tried fdisk -l with my linux pc it says its fat16 for the stick
but when i mention the same in the autopsy for the sticks image
it says"the image is not fat16"

however i used mmls with the image it showed the following!


     Slot    Start        End          Length       Description
00:  -----   0000000000   0000000000   0000000001   Primary Table (#0)
01:  -----   0000000001   0000000031   0000000031   Unallocated
02:  00:00   0000000032   0000254975   0000254944   DOS FAT16 (0x06)

i guess mmls is the only tool to work with usb images
i'l try taking an image of my 4 GB hard disk!
and then work with the autopsy!!</description>
		<content:encoded><![CDATA[<p>s both have the ame hash value!<br />
tried fsstat with the stick but it says &#8220;superblock read: is a directory&#8221;</p>
<p>however i tried fdisk -l with my linux pc it says its fat16 for the stick<br />
but when i mention the same in the autopsy for the sticks image<br />
it says&#8221;the image is not fat16&#8243;</p>
<p>however i used mmls with the image it showed the following!</p>
<p>     Slot    Start        End          Length       Description<br />
00:  &#8212;&#8211;   0000000000   0000000000   0000000001   Primary Table (#0)<br />
01:  &#8212;&#8211;   0000000001   0000000031   0000000031   Unallocated<br />
02:  00:00   0000000032   0000254975   0000254944   DOS FAT16 (0&#215;06)</p>
<p>i guess mmls is the only tool to work with usb images<br />
i&#8217;l try taking an image of my 4 GB hard disk!<br />
and then work with the autopsy!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alexander Geschonneck</title>
		<link>http://geschonneck.com/2006/09/02/the-sleutkit-206-and-autopsy-208/#comment-3169</link>
		<dc:creator>Alexander Geschonneck</dc:creator>
		<pubDate>Tue, 02 Jan 2007 11:49:14 +0000</pubDate>
		<guid isPermaLink="false">http://geschonneck.com/2006/09/02/the-sleutkit-206-and-autopsy-208/#comment-3169</guid>
		<description>It looks that TSK is not recognizing the file systeme of your image. Can you check the hashes of the image and the usb stick? They should be the same. Does fsstat identify the file system on the stick correctly?</description>
		<content:encoded><![CDATA[<p>It looks that TSK is not recognizing the file systeme of your image. Can you check the hashes of the image and the usb stick? They should be the same. Does fsstat identify the file system on the stick correctly?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: anwer</title>
		<link>http://geschonneck.com/2006/09/02/the-sleutkit-206-and-autopsy-208/#comment-3166</link>
		<dc:creator>anwer</dc:creator>
		<pubDate>Tue, 02 Jan 2007 05:52:07 +0000</pubDate>
		<guid isPermaLink="false">http://geschonneck.com/2006/09/02/the-sleutkit-206-and-autopsy-208/#comment-3166</guid>
		<description>hi
i somwhow managed to take a dd image of my usbdrive(124 MB using a linux pc) which
has a fat16 fs!

now i created a new case and a host, with it i added this image
now when i add the image it prompts for the fs type!

i specified it as fat16!
but it says its not a fat16

then i tried by specifying it as a raw image! it worked!
but now it showed only two options: dataunit and keyword search!

while i try to view them(data unit) it says unrecognized file type
but when i give a keyword search it shows the hits!

now what is the problem
where am i going wrong!?!</description>
		<content:encoded><![CDATA[<p>hi<br />
i somwhow managed to take a dd image of my usbdrive(124 MB using a linux pc) which<br />
has a fat16 fs!</p>
<p>now i created a new case and a host, with it i added this image<br />
now when i add the image it prompts for the fs type!</p>
<p>i specified it as fat16!<br />
but it says its not a fat16</p>
<p>then i tried by specifying it as a raw image! it worked!<br />
but now it showed only two options: dataunit and keyword search!</p>
<p>while i try to view them(data unit) it says unrecognized file type<br />
but when i give a keyword search it shows the hits!</p>
<p>now what is the problem<br />
where am i going wrong!?!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alexander Geschonneck</title>
		<link>http://geschonneck.com/2006/09/02/the-sleutkit-206-and-autopsy-208/#comment-3114</link>
		<dc:creator>Alexander Geschonneck</dc:creator>
		<pubDate>Fri, 29 Dec 2006 21:55:27 +0000</pubDate>
		<guid isPermaLink="false">http://geschonneck.com/2006/09/02/the-sleutkit-206-and-autopsy-208/#comment-3114</guid>
		<description>hmmm. In your case in cygwin &lt;code&gt;dd.exe if=\\.\C: of=d:\image.dd&lt;/code&gt; should work.</description>
		<content:encoded><![CDATA[<p>hmmm. In your case in cygwin <code>dd.exe if=\\.\C: of=d:\image.dd</code> should work.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: anwer</title>
		<link>http://geschonneck.com/2006/09/02/the-sleutkit-206-and-autopsy-208/#comment-3111</link>
		<dc:creator>anwer</dc:creator>
		<pubDate>Fri, 29 Dec 2006 10:57:37 +0000</pubDate>
		<guid isPermaLink="false">http://geschonneck.com/2006/09/02/the-sleutkit-206-and-autopsy-208/#comment-3111</guid>
		<description>thanx alexander
i tried that physical drive stuff with dd but still it doesnt work!
anyways 
i'l go with fau and i will get back to you shortly!</description>
		<content:encoded><![CDATA[<p>thanx alexander<br />
i tried that physical drive stuff with dd but still it doesnt work!<br />
anyways<br />
i&#8217;l go with fau and i will get back to you shortly!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alexander Geschonneck</title>
		<link>http://geschonneck.com/2006/09/02/the-sleutkit-206-and-autopsy-208/#comment-3108</link>
		<dc:creator>Alexander Geschonneck</dc:creator>
		<pubDate>Fri, 29 Dec 2006 09:24:05 +0000</pubDate>
		<guid isPermaLink="false">http://geschonneck.com/2006/09/02/the-sleutkit-206-and-autopsy-208/#comment-3108</guid>
		<description>Anwer, you have to use the &lt;b&gt;physical&lt;/b&gt; device as source.

First of all, I suggest to use George Garner's Forensic Acquisition Utilities (&lt;a href="http://users.erols.com/gmgarner/forensics/" target="_blank" rel="nofollow"&gt;FAU&lt;/a&gt;). A more powerfull dd and other tools are included in FAU.

How to address the physical device? Here are some examples for FAU, but the device addressing is the same with "plain" cygwin dd:

&lt;code&gt;
dd.exe if=\\.\PhysicalDrive0 of=d:\images\PhysicalDrive0.img --md5sum --verifymd5

--md5out=d:\images\PhysicalDrive0.img.md5

 

dd if=\\?\Volume{87c34910-d826-11d4-987c-00a0b6741049} of=d:\images\e_drive.img –md5sum –verifymd5 md5out=d:\images\PhysicalDrive0.img.md5

 
dd.exe if=\\.\D: of=d:\images\d_drive.img conv=noerror --sparse --md5sum --verifymd5 –md5out=d:\images\d_drive.img.md5 --log=d:\images\d_drive.log


dd.exe if=\\.\D: of=d:\images\d_drive.img.gz conv=noerror,comp --md5sum --verifymd5 –md5out=d:\images\d_drive.img.md5 --log=d:\images\d_drive.log
&lt;/code&gt;

mount.exe or df.exe brings you the physical device, but you can also use \\.\DRIVELETTER:</description>
		<content:encoded><![CDATA[<p>Anwer, you have to use the <b>physical</b> device as source.</p>
<p>First of all, I suggest to use George Garner&#8217;s Forensic Acquisition Utilities (<a href="http://users.erols.com/gmgarner/forensics/" target="_blank"  onclick="javascript:urchinTracker ('/outbound/comment/users.erols.com');">FAU</a>). A more powerfull dd and other tools are included in FAU.</p>
<p>How to address the physical device? Here are some examples for FAU, but the device addressing is the same with &#8220;plain&#8221; cygwin dd:</p>
<p><code><br />
dd.exe if=\\.\PhysicalDrive0 of=d:\images\PhysicalDrive0.img --md5sum --verifymd5</p>
<p>--md5out=d:\images\PhysicalDrive0.img.md5</p>
<p>dd if=\\?\Volume{87c34910-d826-11d4-987c-00a0b6741049} of=d:\images\e_drive.img –md5sum –verifymd5 md5out=d:\images\PhysicalDrive0.img.md5</p>
<p>dd.exe if=\\.\D: of=d:\images\d_drive.img conv=noerror --sparse --md5sum --verifymd5 –md5out=d:\images\d_drive.img.md5 --log=d:\images\d_drive.log</p>
<p>dd.exe if=\\.\D: of=d:\images\d_drive.img.gz conv=noerror,comp --md5sum --verifymd5 –md5out=d:\images\d_drive.img.md5 --log=d:\images\d_drive.log<br />
</code></p>
<p>mount.exe or df.exe brings you the physical device, but you can also use \\.\DRIVELETTER:</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: anwer</title>
		<link>http://geschonneck.com/2006/09/02/the-sleutkit-206-and-autopsy-208/#comment-3107</link>
		<dc:creator>anwer</dc:creator>
		<pubDate>Fri, 29 Dec 2006 09:07:40 +0000</pubDate>
		<guid isPermaLink="false">http://geschonneck.com/2006/09/02/the-sleutkit-206-and-autopsy-208/#comment-3107</guid>
		<description>s, as i already told u cygwin-dd says " 0 bytes copied since its a directory"
when i try to take an image of my c drive
with this command "dd if=/cygdrive/c/"
but when i do it for a file its successfully done!

does this mean that dd will not work with directories????
if so how am i to take image of my enire drive c: ????</description>
		<content:encoded><![CDATA[<p>s, as i already told u cygwin-dd says &#8221; 0 bytes copied since its a directory&#8221;<br />
when i try to take an image of my c drive<br />
with this command &#8220;dd if=/cygdrive/c/&#8221;<br />
but when i do it for a file its successfully done!</p>
<p>does this mean that dd will not work with directories????<br />
if so how am i to take image of my enire drive c: ????</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alexander Geschonneck</title>
		<link>http://geschonneck.com/2006/09/02/the-sleutkit-206-and-autopsy-208/#comment-3106</link>
		<dc:creator>Alexander Geschonneck</dc:creator>
		<pubDate>Fri, 29 Dec 2006 07:53:21 +0000</pubDate>
		<guid isPermaLink="false">http://geschonneck.com/2006/09/02/the-sleutkit-206-and-autopsy-208/#comment-3106</guid>
		<description>anwer, you need definitely a dd image. You can make it with cygwin-dd, with dd from the Helix CD or with Access Data's FTK-Imager or even with Encase.</description>
		<content:encoded><![CDATA[<p>anwer, you need definitely a dd image. You can make it with cygwin-dd, with dd from the Helix CD or with Access Data&#8217;s FTK-Imager or even with Encase.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: anwer</title>
		<link>http://geschonneck.com/2006/09/02/the-sleutkit-206-and-autopsy-208/#comment-3105</link>
		<dc:creator>anwer</dc:creator>
		<pubDate>Fri, 29 Dec 2006 03:47:31 +0000</pubDate>
		<guid isPermaLink="false">http://geschonneck.com/2006/09/02/the-sleutkit-206-and-autopsy-208/#comment-3105</guid>
		<description>oh yes
autopsy worked- i reconfigured the proxy!
thanx a lot Alexander Geschonneck 
1)but let me know on what image sleuthkit works or how to take an image to work with skeuthkit</description>
		<content:encoded><![CDATA[<p>oh yes<br />
autopsy worked- i reconfigured the proxy!<br />
thanx a lot Alexander Geschonneck<br />
1)but let me know on what image sleuthkit works or how to take an image to work with skeuthkit</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: anwer</title>
		<link>http://geschonneck.com/2006/09/02/the-sleutkit-206-and-autopsy-208/#comment-3104</link>
		<dc:creator>anwer</dc:creator>
		<pubDate>Fri, 29 Dec 2006 03:40:01 +0000</pubDate>
		<guid isPermaLink="false">http://geschonneck.com/2006/09/02/the-sleutkit-206-and-autopsy-208/#comment-3104</guid>
		<description>1)i guess sleuthkit requires an image taken through dd??!!!
if not on which images does sleuthkit work?
2) i have set the browser to bypass the proxy for the given address 
wat else should i do?!</description>
		<content:encoded><![CDATA[<p>1)i guess sleuthkit requires an image taken through dd??!!!<br />
if not on which images does sleuthkit work?<br />
2) i have set the browser to bypass the proxy for the given address<br />
wat else should i do?!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alexander Geschonneck</title>
		<link>http://geschonneck.com/2006/09/02/the-sleutkit-206-and-autopsy-208/#comment-3102</link>
		<dc:creator>Alexander Geschonneck</dc:creator>
		<pubDate>Thu, 28 Dec 2006 16:40:26 +0000</pubDate>
		<guid isPermaLink="false">http://geschonneck.com/2006/09/02/the-sleutkit-206-and-autopsy-208/#comment-3102</guid>
		<description>@anwer: 
1) did you check your browsers proxy config?

2) First of all it's "cygdrive". But, you should use the physical device as the image source.</description>
		<content:encoded><![CDATA[<p>@anwer:<br />
1) did you check your browsers proxy config?</p>
<p>2) First of all it&#8217;s &#8220;cygdrive&#8221;. But, you should use the physical device as the image source.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: forensicman</title>
		<link>http://geschonneck.com/2006/09/02/the-sleutkit-206-and-autopsy-208/#comment-3100</link>
		<dc:creator>forensicman</dc:creator>
		<pubDate>Thu, 28 Dec 2006 15:56:22 +0000</pubDate>
		<guid isPermaLink="false">http://geschonneck.com/2006/09/02/the-sleutkit-206-and-autopsy-208/#comment-3100</guid>
		<description>Why do u want use cywin for making a disk image? There are many tools for windows to do that....
Helix cd
FTK IMager
etc.

For your first problem I don't know why it happpens..</description>
		<content:encoded><![CDATA[<p>Why do u want use cywin for making a disk image? There are many tools for windows to do that&#8230;.<br />
Helix cd<br />
FTK IMager<br />
etc.</p>
<p>For your first problem I don&#8217;t know why it happpens..</p>
]]></content:encoded>
	</item>
</channel>
</rss>
