Re: NTFS forensic analysis on Unix platform

From: Blake Frantz (blakeat_private)
Date: Wed Jul 25 2001 - 16:28:02 PDT

  • Next message: Ben Ford: "Re: Signature on logs/eMail"

    Purhaps there's been some misunderstanding...
    
    It's not *MY* bootdisk in the sense that I wrote/created/engineered
    or any of the above.  It's simply a disk I have found useful in the past
    and suggested it as a starting point to load the NTFS partition.
    
    I make no claims of having *anything* to do with its creation, and I hope
    I'm making that fact very clear now.
    
    I posted the the link to the packethack domain because I simply don't
    remember where/who I got it from without booting a machine off it.
    
    -Blake
    
    ================================================================= 
    The Government, like diapers, should be replaced regularly, and
    often for the same reasons. 
    
    On Thu, 26 Jul 2001, Kris Carlier wrote:
    
    > Blake,
    > 
    > > I have a linux floppy image that mounts NTFS partitions and allows the
    > > user to replace any password in the (non-syskeyed) SAM.  Purhaps this disk
    > > can provide some info on how to mount the NTFS partition.
    > > 
    > > You can download it at:
    > > www.packethack.com/bd990404.zip
    > 
    > it may be coincidental, but from the looks of it, I'd say this is Petter
    > Nordahl's bootdisk, but a very old one. Check out home.eunet.no/~pnordahl/
    > 
    > kr=
    > 
    >                    \\\___///
    >                   \\  - -  //
    >                    (  @ @  )
    >  +---------------oOOo-(_)-oOOo-------------+
    >  |        kris carlier - krisat_private    |
    >  |   Freedom of speech has been suspended  |
    >  |          [RESUME] [OK] [CANCEL]         |
    >  | KC62-RIPE         SMS: +32-475-61.43.05 |
    >  +------------------------Oooo-------------+
    >                   oooO   (   )
    >                  (   )    ) /
    >                   \ (    (_/
    >                    \_)
    > 
    > "In 1555, Nostradamus wrote: 'Come the millennium, month 12, in the home of
    > greatest power, the village idiot will come forth to be acclaimed the
    > leader.'"
    > 
    > 
    
    
    -----------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    



    This archive was generated by hypermail 2b30 : Thu Jul 26 2001 - 08:58:42 PDT