Never mind, Drew indicated that Helix 2.0 and KnTTools would be able to do a RAM dump in Vista. But that's the point - Cygwin doesn't come in Vista yet and my understanding is it's needed for Linux to run in a Win environment. Apparently Vista writes to memory different too I hear so Cygwin may not work??? Never mind - i'll get KnTTools and wait anxiously for 2.0.
Mikeypopo,
"Cygwin doesn't come in Vista yet and my understanding is it's needed for Linux to run in a Win environment. "
Cygwin doesn't come by default on *any* Windows distro that I'm aware of. And yes, there are some Linux/*nix-based tools that have been compiled for the Windows environment using Cygwin as a base.
"Apparently Vista writes to memory different too I hear so Cygwin may not work???"
*EVERY* version of Windows "writes to memory" in a different manner than the other versions. There are not only differences between Win2000, XP and Win2003, but also between service packs (as with XP).
However, this has nothing whatsoever to do with Cygwin.
H
I may be missing something here - but Live Linux CDs don't need an operating system - they ARE the operating system. That's the whole point of a Live CD.
A
A,
You're right…but to whom are you responding?
H
Harlan,
Anybody that will listen P
A
A,
Okay, then…what's the point? The discussion was more along the lines of the Windows side of Helix (not bootable) and using the tools on that side to collect the contents of physical memory. The more recent portions of the thread don't have much of anything to do with Live Linux CDs.
I'm not saying that your post isn't valid…I'm only asking that for etiquette purposes, it's usually an accepted practice to start a new thread when pursing a new subject.
Thanks,
H
ac_forensics,
Did you ever get that info on Helix that you were asking about? I am also interested in whatever issues it may have. I am also interested in SPADA issues too, so if you happen to find those I would love to hear them as well. I am really only seriously worried about what issues might exist with maintaining the integrity of the data. I know most Live IR distros disable the auto mounting of the swap partition, but I've heard rumors that some may actually change the hash on some journaled file systems without mounting them read/write.
For anyone who has information on this or the other issues please let me know.
thanks,
christian…