Deft Linux v 5.1 on...
 
Notifications
Clear all

Deft Linux v 5.1 on USB?

18 Posts
11 Users
0 Reactions
3,572 Views
(@gzobell)
New Member
Joined: 15 years ago
Posts: 1
 

I couldn't get the Deft 5.1 ISO to boot from CD, let alone USB. I download 5.x and that worked fine.

Grant


   
ReplyQuote
(@rampage)
Reputable Member
Joined: 17 years ago
Posts: 354
 

I'm not in the team and therefore not directly involved in the pre-release testings.

i played my tests and validated the tool before using it of course, and it never happened to me that any drive was altered after having booted the system with deft.

NTFS devices shouldn't be an issue couse the NTFS-3g driver runs in user space afaik, about the linux FS it didn't happen to me, i've hashed the drive before and after having used deft and the hashes was matching.

if you have any experience of such issues i think the best thing to do would be to report it directly to the devs


   
ReplyQuote
(@thefuf)
Reputable Member
Joined: 17 years ago
Posts: 262
 

Is anyone aware of this information about Deft being NOT forensically sound

DEFT developers fixed Ext recovery issues long time ago. Currently, DEFT only runs a code from connected HDDs under very rare conditions )


   
ReplyQuote
binarybod
(@binarybod)
Reputable Member
Joined: 17 years ago
Posts: 272
 

Currently, DEFT only runs a code from connected HDDs under very rare conditions )

That wouldn't be this paper would it? A number of debian based systems that use casper scripts are vulnerable.

CAINE will be fixing this in version 2.0. I don't know about DEFT (which was also identified as vulnerable).

Paul )


   
ReplyQuote
(@thefuf)
Reputable Member
Joined: 17 years ago
Posts: 262
 

A number of debian based systems that use casper scripts are vulnerable.

grml silently included the fix in the recent version ( http//translate.google.com/translate?sl=ru&tl=en&u=http%3A%2F%2Fwww.risspa.ru%2Fnode%2F205 ).

DEFT developers received a preliminary patch in January 2010, but didn't include it in the release for some reason. CAINE team already developed a patch for CD version only. And no updates from developers of other distros )


   
ReplyQuote
(@farmerdude)
Estimable Member
Joined: 20 years ago
Posts: 242
 

Yes, it's not news for those who test these CDs. Someone who was putting out their new CD put a marketing blitz (what I call it) out about it and folks who weren't testing were caught unaware. Interestingly some Slackware-based CDs did not exhibit this behavior. 😉

Cheers!

farmerdude

www.onlineforensictraining.com

www.forensicbootcd.com


   
ReplyQuote
nannib
(@nannib)
Active Member
Joined: 17 years ago
Posts: 13
 

Caine 2.0 is patched!
http//www.caine-live.net


   
ReplyQuote
binarybod
(@binarybod)
Reputable Member
Joined: 17 years ago
Posts: 272
 

Update removed - pointless posting oops

Paul


   
ReplyQuote
Page 2 / 2
Share: