Forensic Focus - Computer Forensics, Computer Forensic Training, Digital Forensics
LoginRegisterForumsColumnistsPapersEducationGraduatesReviewsInterviewsNewsletterJobsEventsBlogAdvertise
Search Forensic Focus
Custom Search

Find us on Facebook
Follow Forensic Focus on Twitter
Columnists
"I erred." "I was mistaken."
Craig Ball
Single Sign On
Simon Biles
Copyright and games console modification
Dan Gaskell
To GUI or not to GUI?
Chris Hargreaves
'Web 2.0' as evidence
Sean McLinden
Sometimes it’s all about timing
Sam Raincock
Avoiding common job application errors
David Sullivan
Scalability: A Big Headache
Dominik Weber
Graduate Recruitment

computer forensics graduate jobs

Main Menu
MY ACCOUNT
COMMUNITY
EMPLOYMENT
EDUCATION
RESOURCES
MISC
Follow Forensic Focus

Join newsletter

Join LinkedIn group

Follow on Twitter

Subscribe to news

Subscribe to forums

Subscribe to blog

Subscribe to tweets

Members' blogs

External feeds

Bookmark & share: Bookmark and Share

Computer Forensics Newsletter
Newsletter

You must be a
registered user
to receive our newsletter

Register Now!

volatile memory on windows
Go to page 1, 2  Next
Post new topic   Reply to topic   Printer Friendly Page     Forum Index -> Open Source and Freeware
View previous topic :: View next topic  
Author Message
koko
Newbie


Joined: Dec 02, 2005
Posts: 22
Location: NYC

PostPosted: Wed Jan 25, 2006 11:02 am    Post subject: volatile memory on windows Reply with quote

i am just looking for some recommendations of open source software that can grab the volatile memory (RAM) from a windows machine.
Back to top
View user's profile
keydet89
Senior Member


Joined: Oct 19, 2004
Posts: 2373
Location: NoVA

PostPosted: Wed Jan 25, 2006 12:50 pm    Post subject: Re: volatile memory on windows Reply with quote

dd

Harlan
Back to top
View user's profile Visit poster's website AIM Address
keydet89
Senior Member


Joined: Oct 19, 2004
Posts: 2373
Location: NoVA

PostPosted: Wed Jan 25, 2006 12:52 pm    Post subject: Re: volatile memory on windows Reply with quote

More specifically...

users.erols.com/gmgarner/forensics/

Now, the $64 question...what are you planning to do with it once you have it? Given the discussions that have taken place here, and on other boards, I'm sincerely curious about this topic.

Harlan
Back to top
View user's profile Visit poster's website AIM Address
koko
Newbie


Joined: Dec 02, 2005
Posts: 22
Location: NYC

PostPosted: Thu Jan 26, 2006 3:45 pm    Post subject: Re: volatile memory on windows Reply with quote

thank you for the info. i didn't realize you could do it with dd.

i hope i don't disappoint you when i say that my intentions in using it right now are just educational. i'm just going to run it on my machine, etc.
Back to top
View user's profile
farmerdude
Senior Member


Joined: Jan 13, 2006
Posts: 231
Location: USA

PostPosted: Fri Jan 27, 2006 12:14 am    Post subject: Reply with quote

Hi koko,

You can use 'dd' for some memory, but not all. Not all memory has an EOF marker, and 'dd' doesn't like that. Memory can have holes ... and 'dd' won't like that either.

You're much better off using a tool written for dumping memory, reading one page at a time so as to minimize your affect on the system memory. 'memdump' is one such tool.

regards,

farmerdude
Back to top
View user's profile
keydet89
Senior Member


Joined: Oct 19, 2004
Posts: 2373
Location: NoVA

PostPosted: Fri Jan 27, 2006 7:37 am    Post subject: Re: volatile memory on windows Reply with quote

Thomas,

Are you referring to the 'memdump' that comes with TCT?
www.porcupine.org/fore...s/tct.html

Harlan
Back to top
View user's profile Visit poster's website AIM Address
farmerdude
Senior Member


Joined: Jan 13, 2006
Posts: 231
Location: USA

PostPosted: Fri Jan 27, 2006 8:38 am    Post subject: Re: volatile memory on windows Reply with quote

memdump by Wietse is the tool I mentioned in my post. I know it's separate from TCT, unless recently he's added it into the package. We spoke of grabbing memory a few years back at AusCERT and subsequently he released memdump. There are others, but this works very well.

regards,

farmerdude
Back to top
View user's profile
keydet89
Senior Member


Joined: Oct 19, 2004
Posts: 2373
Location: NoVA

PostPosted: Fri Jan 27, 2006 8:43 am    Post subject: Re: volatile memory on windows Reply with quote

Thomas,

Given that the 'memdump' you mentioned is for *nix systems, is there a version available for Windows, per the subject of the thread?

Harlan
Back to top
View user's profile Visit poster's website AIM Address
psycko
Newbie


Joined: Jan 02, 2006
Posts: 16
Location: paris

PostPosted: Tue Feb 07, 2006 1:57 pm    Post subject: Re: volatile memory on windows Reply with quote

Hi !
There's a freeware DOS version, located here

www.tssc.de/download/p...emdump.zip

Regards

R1
Back to top
View user's profile
farmerdude
Senior Member


Joined: Jan 13, 2006
Posts: 231
Location: USA

PostPosted: Tue Feb 07, 2006 8:37 pm    Post subject: Re: volatile memory on windows Reply with quote

R1 beat me to the reply. That link appears to work.

I have used memdump compiled for Windows as well (DOS version) in addition to a proprietary dumper, one page at a time.

Download from the R1 link and test it out.

regards,

farmerdude
Back to top
View user's profile
Display posts from previous:   
Post new topic   Reply to topic   Printer Friendly Page     Forum Index -> Open Source and Freeware All times are GMT - 6 Hours
Go to page 1, 2  Next
Page 1 of 2


Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


Use of this website signifies your agreement to the Terms of Use/Privacy Policy available here.

All logos and trademarks in this site are property of their respective owner. The comments are property of their posters, all the rest © 2010 Forensic Focus


Interactive software released under GNU GPL, Code Credits, Privacy Policy
.: fisubsilver shadow phpbb2 style by Daz :: CPG-Nuke port by norseman :: ported to CPG-Dragonfly by jamin :.