CAINE 1.5 Installed and Rifiuti to analyze INFO2 files

View previous topic View next topic Go down

CAINE 1.5 Installed and Rifiuti to analyze INFO2 files

Post  joetekno on Tue Mar 09, 2010 8:42 pm

Rifiuti can be used for the reconstruction of a suspect drives Recycle Bin. Analyzing the INFO2 file may allow you to find the deleted file(s) / folder(s) original location, size, and deleted time.

USAGE

Note that spaces below are exaggerated for readability.

Basic Usage Example: rifiuti INFO2

You could script analyzing multiple files like this...

#---BEGIN SCRIPT---
echo “Where is the drive, volume, or image file to be analyzed mounted?”
echo “example: /media/sda1”
read VOLUME

find $VOLUME -name INFO2 > temp
sed ‘s/ /\\ /g’ temp > foundfiles
LINES=`wc -l foundfiles | cut -d " " -f 1`
COUNT=0
while [ $COUNT -lt $LINES ]; do
COUNT=$(( $COUNT + 1 ))
echo "rifiuti " >> pre
done

paste pre foundfiles post > RIFIUTI.sh
chmod 700 RIFIUTI.sh
./RIFIUTI.sh > INFO2Evidence.txt

less INFO2Evidence.txt
#---END SCRIPT---
avatar
joetekno

Number of posts : 50
Località : Wisconsin, United States
Registration date : 2009-02-19

View user profile http://network.nwtc.edu

Back to top Go down

Re: CAINE 1.5 Installed and Rifiuti to analyze INFO2 files

Post  MAX.KNIGHT68 on Thu Dec 20, 2012 9:13 pm

joetekno wrote:Rifiuti can be used for the reconstruction of a suspect drives Recycle Bin. Analyzing the INFO2 file may allow you to find the deleted file(s) / folder(s) original location, size, and deleted time.

USAGE

Note that spaces below are exaggerated for readability.

Basic Usage Example: rifiuti INFO2

You could script analyzing multiple files like this...

#---BEGIN SCRIPT---
echo “Where is the drive, volume, or image file to be analyzed mounted?”
echo “example: /media/sda1”
read VOLUME

find $VOLUME -name INFO2 > temp
sed ‘s/ /\\ /g’ temp > foundfiles
LINES=`wc -l foundfiles | cut -d " " -f 1`
COUNT=0
while [ $COUNT -lt $LINES ]; do
COUNT=$(( $COUNT + 1 ))
echo "rifiuti " >> pre
done

paste pre foundfiles post > RIFIUTI.sh
chmod 700 RIFIUTI.sh
./RIFIUTI.sh > INFO2Evidence.txt

less INFO2Evidence.txt
#---END SCRIPT---

Hello (again) ...
Let me get this straight ...
What is "Waste"? is a bash script?
is perhaps the one shown above between the lines
# --- BEGIN SCRIPT ---
to
# --- END SCRIPT ---
??? Surprised
Thanks in advance and happy holidays.

MAX.KNIGHT68

Number of posts : 11
Age : 49
Località : Taranto
Registration date : 2012-12-02

View user profile

Back to top Go down

bash shell script

Post  joetekno on Fri Dec 21, 2012 3:25 am

Yes, the code between the lines is a bash shell script
avatar
joetekno

Number of posts : 50
Località : Wisconsin, United States
Registration date : 2009-02-19

View user profile http://network.nwtc.edu

Back to top Go down

Re: CAINE 1.5 Installed and Rifiuti to analyze INFO2 files

Post  Sponsored content


Sponsored content


Back to top Go down

View previous topic View next topic Back to top

- Similar topics

 
Permissions in this forum:
You cannot reply to topics in this forum