Notifications
Clear all

DD and FTK

18 Posts
5 Users
0 Reactions
5,774 Views
hogfly
(@hogfly)
Reputable Member
Joined: 21 years ago
Posts: 287
Topic starter  

Andy,
Indeed, but this is a separate copy specifically created for testing FTK and a disk spidering tool we have written. I have my forensically sound image stored elsewhere currently.
Thanks again.


   
ReplyQuote
 Andy
(@andy)
Reputable Member
Joined: 21 years ago
Posts: 357
 

Understood…… Just out of interest, what does your spidering tool do?

Andy


   
ReplyQuote
hogfly
(@hogfly)
Reputable Member
Joined: 21 years ago
Posts: 287
Topic starter  

It's a server-client tool that we use to search for sensitive data on web servers and sql servers. written in perl, it attempts some sql injection to see what it can find on a public server. However, it functions on a mounted disk image.
We use helix almost exclusively, so we mount the dd image on the loopback, and scour the disk with the spider tool. It matches based on regexes, and spits out 1k surrounding the match in to a logfile.


   
ReplyQuote
nickfx
(@nickfx)
Estimable Member
Joined: 20 years ago
Posts: 131
 

Hogfly

Sounds interesting are you planning to release the tool?

Nick


   
ReplyQuote
hogfly
(@hogfly)
Reputable Member
Joined: 21 years ago
Posts: 287
Topic starter  

nick,
it's something that would have to be discussed internally, but I don't see why anyone here wouldn't want to release it.


   
ReplyQuote
nickfx
(@nickfx)
Estimable Member
Joined: 20 years ago
Posts: 131
 

I would certainly like a copy of the tool and proceedure if that becomes possible.

Nick


   
ReplyQuote
(@Anonymous)
Guest
Joined: 1 second ago
Posts: 0
 

I would certainly like a copy of the tool and proceedure if that becomes possible.

Nick

hi,

the imager is a free download from accessdata.com and does not require the hardware token to run.. it is only required for the access data analysis suites such as prtk and ftk etc.


   
ReplyQuote
nickfx
(@nickfx)
Estimable Member
Joined: 20 years ago
Posts: 131
 

flytnx,

Yeah I use FTK imager all the time I was referring to the spidering tool that hogfly was describing.

Thanks anyway.

Nick


   
ReplyQuote
Page 2 / 2
Share: