Forensic Focus - Computer Forensics, Computer Forensic Training, Digital Forensics
LoginRegisterForumsColumnistsPapersEducationGraduatesReviewsInterviewsNewsletterJobsEventsBlogAdvertise
Search Forensic Focus
Custom Search

Find us on Facebook
Follow Forensic Focus on Twitter
Columnists
"I erred." "I was mistaken."
Craig Ball
Single Sign On
Simon Biles
Copyright and games console modification
Dan Gaskell
To GUI or not to GUI?
Chris Hargreaves
'Web 2.0' as evidence
Sean McLinden
Sometimes it’s all about timing
Sam Raincock
Avoiding common job application errors
David Sullivan
Scalability: A Big Headache
Dominik Weber
Graduate Recruitment

computer forensics graduate jobs

Main Menu
MY ACCOUNT
COMMUNITY
EMPLOYMENT
EDUCATION
RESOURCES
MISC
Follow Forensic Focus

Join newsletter

Join LinkedIn group

Follow on Twitter

Subscribe to news

Subscribe to forums

Subscribe to blog

Subscribe to tweets

Members' blogs

External feeds

Bookmark & share: Bookmark and Share

Computer Forensics Newsletter
Newsletter

You must be a
registered user
to receive our newsletter

Register Now!

CAINE 1.0 is now available
Post new topic   Reply to topic   Printer Friendly Page     Forum Index -> General Discussion
View previous topic :: View next topic  
Author Message
douglasbrush
Senior Member


Joined: Feb 19, 2009
Posts: 577
Location: New York, NY

PostPosted: Fri Oct 30, 2009 6:42 am    Post subject: CAINE 1.0 is now available Reply with quote

CAINE (Computer Aided INvestigative Environment) is a GNU/Linux live distribution created by Giancarlo Giustini as a project of Digital Forensics for Interdepartment Center for Research on Security (CRIS), supported by the University of Modena and Reggio Emilia.



www.caine-live.net/

_________________
------------------------
Douglas A. Brush, CFC, EnCE
The Digital Forensic Group
twitter.com/douglasbrush
www.TheDigitalForensicGroup.com
blog.TheDigitalForensicGroup.com
Back to top
View user's profile Visit poster's website Yahoo Messenger
thefuf
Newbie


Joined: Aug 01, 2008
Posts: 29
Location: Russia, Moscow

PostPosted: Fri Oct 30, 2009 7:52 am    Post subject: Re: CAINE 1.0 is now available Reply with quote

This is a first forensically sound CAINE release. Unlike many other "forensic" Live CDs it does not recover file systems during the boot Smile

So stay up to date.
Back to top
View user's profile
seawolf
Newbie


Joined: May 20, 2009
Posts: 5
Location: Chester, UK

PostPosted: Sun Nov 01, 2009 2:58 pm    Post subject: Re: CAINE 1.0 is now available Reply with quote

For what it's worth, I've started a personal blog on digital forensics with open-source, and it just so happens I've spent a couple of hours with CAINE 1 too. It's hardly a comprehensive review but I'd love any feedback you may have, especially if you have used it to perform acquisitions or analyses.

There is a note about its handling of filesystems. One of the team have been in contact, too.

Thanks!
Ben @ www.seawolfsanctuary.com

_________________
Ben Arnold
Student @ Chester University
Junior Forensic Investigator & Developer @ Fiasa Ltd.
seawolf @ twitter & identi.ca
www.seawolfsanctuary.com
Back to top
View user's profile Visit poster's website
kovar
Senior Member


Joined: Sep 08, 2007
Posts: 625
Location: San Francisco, CA * Central Illinois

PostPosted: Mon Nov 02, 2009 12:10 am    Post subject: Re: CAINE 1.0 is now available Reply with quote

Greetings,

A minor complaint. If your review, and the comments, are moved off the site it becomes more difficult to find all, or most, of the information in one place. One of the things I like about FF, and the CCE list, is that I can search them and usually find the entire discussion thread in one place.

I also understand the desire to drive traffic to your blog, particularly since I've been considering blogging myself.

I wonder if there is a happy medium?

-David

_________________
CISSP, CCE, EnCE, Licensed Private Investigator (CA)
Back to top
View user's profile Visit poster's website
seawolf
Newbie


Joined: May 20, 2009
Posts: 5
Location: Chester, UK

PostPosted: Mon Nov 02, 2009 5:33 am    Post subject: Re: CAINE 1.0 is now available Reply with quote

kovar wrote:
It becomes more difficult to find all, or most, of the information in one place. One of the things I like about FF, and the CCE list, is that I can search them and usually find the entire discussion thread in one place.

I also understand the desire to drive traffic to your blog, particularly since I've been considering blogging myself.

I wonder if there is a happy medium?

I do understand your point and I agree that everything has it's place (e.g. experiences of members here) but publishing it elsewhere opens up commenting & discussion to a wider audience and perhaps inviting others in to the conversation. That, and being I haven't used it in a more professional context, are the only reasons I haven't discussed it directly on this board.
I linked to it, as I'm sure you see, to make those interested aware that it is there. I'm pretty sure that comments are open to anyone as a guest so there aren't any restrictions.

I do see the point you're making and agree with it, it would be good to collect it together. For now though, links are all I have!

_________________
Ben Arnold
Student @ Chester University
Junior Forensic Investigator & Developer @ Fiasa Ltd.
seawolf @ twitter & identi.ca
www.seawolfsanctuary.com
Back to top
View user's profile Visit poster's website
farmerdude
Senior Member


Joined: Jan 13, 2006
Posts: 231
Location: USA

PostPosted: Mon Nov 02, 2009 4:47 pm    Post subject: Re: CAINE 1.0 is now available Reply with quote

Quote::
This is a first forensically sound CAINE release. Unlike many other "forensic" Live CDs it does not recover file systems during the boot

Where is your documentation to support this statement (IE, which "many other "forensic" Live CDs" recover file systems during the boot process)?


Cheers!

farmerdude

www.onlineforensictraining.com

www.forensicbootcd.com
Back to top
View user's profile
thefuf
Newbie


Joined: Aug 01, 2008
Posts: 29
Location: Russia, Moscow

PostPosted: Mon Nov 02, 2009 4:54 pm    Post subject: Re: CAINE 1.0 is now available Reply with quote

Quote::
Where is your documentation to support this statement (IE, which "many other "forensic" Live CDs" recover file systems during the boot process)?

Here (on FF) and here: www.computer-forensics...gators.pdf
Back to top
View user's profile
farmerdude
Senior Member


Joined: Jan 13, 2006
Posts: 231
Location: USA

PostPosted: Mon Nov 02, 2009 5:24 pm    Post subject: Re: CAINE 1.0 is now available Reply with quote

A few random points ...

1) The topic of mounting or recovering a file system seems to be much like steganography ... in that there's seemingly a bit of hype about it but in the end not much activity. Perhaps with mounting this is because the acquisition of a target does not depend upon its mount status? You aren't required to mount a file system to authenticate it nor acquire it. Additionally, many forensic applications (such as SMART by ASR Data) also do not require the target file system to be mounted in order to process the data within it.

I wouldn't get too hyped on mounting/recovering read-only vs. true read-only. Understanding the file system, the recovery process, and what may be updated and why is important. Being able to articulate that knowledge is key. Killing yourself to live ...

2) An interesting thought about "all these Linux forensic CDs" ... depending upon how they handle mounting and recovery of file systems ... the marketers behind many of them seem to focus on the target, but what of the destination? Careful consideration of what massaging has gone on for the mounting and recovery _should_ be undertaken by the user before use in the field. Anyone want to mount a corrupt ext3 destination file system to write an image file to using a CD that has disabled file system recovery, only to learn later in the lab their image file is junk? Hmm ...


As for the referenced paper I have some feedback and questions, but I've got Halloween candy to dine on and will update later.

Cheers!

farmerdude

www.onlineforensictraining.com

www.forensicbootcd.com
Back to top
View user's profile
jamie
Site Admin


Joined: Aug 18, 2004
Posts: 968

PostPosted: Mon Nov 02, 2009 5:40 pm    Post subject: Re: CAINE 1.0 is now available Reply with quote

@David (and others) there's also some thoughts on CAINE from BJ here: www.forensicfocus.com/...-to-helix3
Back to top
View user's profile Visit poster's website
nannib
Newbie


Joined: Mar 01, 2008
Posts: 4
Location: Italy

PostPosted: Tue Nov 03, 2009 2:15 am    Post subject: Re: CAINE 1.0 is now available Reply with quote

You can find all the mount policies and the How-To here:

www.caine-live.net/page8/page8.html

Nanni Bassetti
Back to top
View user's profile Visit poster's website
Display posts from previous:   
Post new topic   Reply to topic   Printer Friendly Page     Forum Index -> General Discussion All times are GMT - 6 Hours
Page 1 of 1


Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


Use of this website signifies your agreement to the Terms of Use/Privacy Policy available here.

All logos and trademarks in this site are property of their respective owner. The comments are property of their posters, all the rest © 2010 Forensic Focus


Interactive software released under GNU GPL, Code Credits, Privacy Policy
.: fisubsilver shadow phpbb2 style by Daz :: CPG-Nuke port by norseman :: ported to CPG-Dragonfly by jamin :.