Re: Forensics on Word Documents

From: crazybarryat_private
Date: Wed Sep 19 2001 - 07:10:34 PDT

  • Next message: Computer Investigator: "Linux Forensics"

    Just downloaded Strings from sysinternals.  Very cool :)  
    But I do have a question about it....
    
    Although it gives me lots of information about the file there still seems
    to be lots of information missing.  Such as the actual text of the
    document.  Also, I believe that the printer that the document was defaulted
    to print to is also included as part of the document.  So question
    is....where's the rest of the stuff??
    
    Thanks,
    Barry 
    
    
    Jonathan Bloomquist writes:
    
    > i agree - strings is also available for win32 from
    > sysinternals:
    > 
    > http://www.sysinternals.com/ntw2k/source/misc.shtml
    > 
    > --- jamie rishaw <jamieat_private> wrote:
    > > running it through UNIX 'strings' is always one of
    > > the first things I
    > > do to any document or file that I don't know of --
    > > it's invaluable in
    > > a lot of things..
    > > 
    > > jamie
    > > 
    > > On Fri, Sep 14, 2001 at 03:57:56PM +1000, Nicole
    > > Haywood wrote:
    > > > I've got to do a comparison on a couple of
    > > versions of word documents to try to determine which
    > > was created first etc.
    > > > 
    > > > Is there anything any one can suggest I look at in
    > > a word document other than creation date and
    > > revisions etc.
    > > > 
    > > > Thanks, 
    > > > 
    > > > Nicole
    > 
    > 
    > __________________________________________________
    > Terrorist Attacks on U.S. - How can you help?
    > Donate cash, emergency relief information
    > http://dailynews.yahoo.com/fc/US/Emergency_Information/
    > 
    > -----------------------------------------------------------------
    > This list is provided by the SecurityFocus ARIS analyzer service.
    > For more information on this free incident handling, management 
    > and tracking system please see: http://aris.securityfocus.com
    > 
    
    
    CFE, MCSE, MCP+Internet
    
    -----------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    



    This archive was generated by hypermail 2b30 : Wed Sep 19 2001 - 09:03:51 PDT