Re: Rooted Linux Box Foresensics Questions

From: David Douthitt (ssratat_private)
Date: Thu Aug 23 2001 - 08:25:00 PDT

  • Next message: Simon Wellborne: "Following the IP trail"

    Nick Lange wrote:
    
    > anyone know of any single floppy disk distro's designed for forensics
    > containing such things as network drivers and fs stuff for mounting and
    > transferring information off the machine so I can figure out exactly what
    > happneed w/o screwing up evidence?
    
    There is a year-old variant of the Linux Router Project (LRP) called
    Oxygen which contains a lot of material you might find useful.  It's a
    single disk Linux boot with multiple additional (optional) "package"
    disks which provide a lot of network diagnostic utilities, as well as
    some that provide "system rescue" utilities.
    
    Included network diagnostics tools are too many to list; some examples
    are netcat, cryptcat, ftp, nmap, arping, arpwatch, axfer, etc.  Included
    system rescue tools include (but aren't limited to): e2fs tools, lilo,
    minicom, proftpd, strings, zip, netcat, file, and more; the e2fs tools
    include lsattr, chattr, debugfs, e2label, extend, mkfs.ext2, and more...
    
    Note that I am the developer; if there are any problems with this
    product, I'd like to hear of it.
    
    It is available from http://leaf.sourceforge.net/pub/oxygen/ and remains
    in active development.
    
    -----------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    



    This archive was generated by hypermail 2b30 : Thu Aug 23 2001 - 11:01:48 PDT