|
Forensics
Linux, dd, and image file Apr 01 2003 04:31PM Sabol, Paul (PSABOL mgmmirage com) (6 replies) Re: Linux, dd, and image file Apr 02 2003 09:02AM Birger Toedtmann (btoedtmann exp-math uni-essen de) |
|
|
Privacy Statement |
> ...and on Tue, Apr 01, 2003 at 08:31:10AM -0800, Sabol, Paul used the keyboard:
> You should check out the partition table using "fdisk -l /dev/hdc",
> then "dd if=/dev/hdc1 ..." if the NTFS partition is the first and/or
> the only one on that disk, or use the corresponding partition number.
Paul,
I agree that you likely grabbed the entire disk instead of the
partitions. I wrote an article in the last Sleuth Kit Informer about
extracting partitions from a disk image using 'dd' and 'fdisk' that
provides more info on doing this on a Linux system.
http://www.sleuthkit.org/informer/sleuthkit-informer-2.html#split
http://sleuthkit.sourceforge.net/informer/sleuthkit-informer-2.html#spli
t
brian
-----------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com
[ reply ]