Re: Possible forensic issue with grub and RH8.0

From: Ben Boulanger (benat_private)
Date: Fri Jan 10 2003 - 09:51:46 PST

  • Next message: Stephen Menard: "Re: Possible forensic issue with grub and RH8.0"

    On Tue, 2003-01-07 at 22:46, Hovis Chasteen wrote: 
    > title Red Hat Linux 8.0 (2.4.18-14)
    > 	root (hd0,1)
    > 	kernel /vmlinuz-2.4.18-14 ro root=LABEL=/
    > 	initrd /initrd-2.4.18-14.img
    > 
    > I changed the kernel line to read “kernel
    > /vmlinuz-2.4.18-14 ro root=/dev/hda5” (hda5 is my root
    > partition). I rebooted the system and everything is
    > now as expected.  My point here is obvious. If I had
    > installed a suspect hard drive on this stock install I
    > could be working on the original evidence and loose
    > data integrity. Not a good thing.
    Are you certain that you don't have your original drive on the secondary
    IDE channel or something like that?  It seems consistent with that kind
    of a problem, as I've had no similar problems adding drives with RH8 &
    grub. 
    
    Ben Boulanger 
    
    
    
    -----------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    



    This archive was generated by hypermail 2b30 : Sat Jan 11 2003 - 12:55:10 PST