Linux-based hexadec...
 
Notifications
Clear all

Linux-based hexadecimal search tool

8 Posts
2 Users
0 Reactions
1,421 Views
(@liguoroa)
Estimable Member
Joined: 16 years ago
Posts: 43
Topic starter  

Dear All,
does anybody can suggest me an opensource tool to search for a sequence of hexadecimal digits into a disk raw image?

I would like to have as output the blocks in which the sequence has been found.

Best Regards
Andrea Liguoro


   
Quote
HexDrugsRockNRoll
(@hexdrugsrocknroll)
Trusted Member
Joined: 17 years ago
Posts: 60
 

The SIFT workstation comes with Bless Hex Editor installed.


   
ReplyQuote
(@liguoroa)
Estimable Member
Joined: 16 years ago
Posts: 43
Topic starter  

Dear HexDrugsRockNRoll,
thank you very much for your answer.
I will install Bless Hex Editor on my Ubuntu-based analysis computer.

Just a question this tool is able to analyze a raw disk having a size of 500 MB and perform an hexadecimal search on it?

Best Regards,
Andrea Liguoro


   
ReplyQuote
HexDrugsRockNRoll
(@hexdrugsrocknroll)
Trusted Member
Joined: 17 years ago
Posts: 60
 

I haven't used it, I'm afraid, so can't confirm whether or not it will. I can only suggest you try it on a copy of your evidence once you've installed.

Hope this helps.


   
ReplyQuote
(@liguoroa)
Estimable Member
Joined: 16 years ago
Posts: 43
Topic starter  

I'll try and give you a feedback.

Thanks a lot


   
ReplyQuote
HexDrugsRockNRoll
(@hexdrugsrocknroll)
Trusted Member
Joined: 17 years ago
Posts: 60
 

Feedback would be great. Thanks a lot.


   
ReplyQuote
(@liguoroa)
Estimable Member
Joined: 16 years ago
Posts: 43
Topic starter  

I installed BlessHex editor on my analysis virtual machine (based on Deft 8.2 distribution) and opened the raw image file.

This tool has a good usability and I have easily found hexadecimal data on the file.
The raw image file was quite small (98,4 MB), since it was a test data set downloaded from http//www.cfreds.nist.gov/.

I found some interesting information about hexadecimal editor on http//en.wikipedia.org/wiki/Comparison_of_hex_editors

I also downloaded and installed wxHexEditor http//www.wxhexeditor.org/home.php. This editor could be useful when we need to analyse big raw file images since its website claim the following interesting features

"It uses 64 bit file descriptors (supports files or devices up to 2^64 bytes , means some exabytes but tested only 1 PetaByte file (yet). ).
It does NOT copy whole file to your RAM. That make it FAST and can open files (which sizes are Multi Giga < Tera < Peta < Exabytes)
…..
Memory Usage Currently ~25 MegaBytes while opened multiple > ~8GB files"

I hope it could be useful

Best Regards,
Andrea Liguoro


   
ReplyQuote
HexDrugsRockNRoll
(@hexdrugsrocknroll)
Trusted Member
Joined: 17 years ago
Posts: 60
 

This is really excellent feedback. Thanks a lot for taking the time to write back.


   
ReplyQuote
Share: