Re: memdump - UNIX memory dumper

Andreas Bunten <[email protected]> Mon, 5 Jan 2004 13:11:54 +0100 (MET)
Newsgroups gmane.comp.security.forensics.tct
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----

On Thu, 1 Jan 2004, Wietse Venema wrote:

(...)
> What can you find in a system memory dump? Bits from the operating
> system, from running processes, and from every file and directory
> that has been accessed recently. Depending on the operating system
> you may even find some information from deleted files and exited
> processes, although that information tends to be short-lived.
(...)

This sounds very usefull!

Are there tools or any help on how to extract these usefull bits from
the dump? Like getting a list of processes and their allocated pages
directly from the kernel structures ... Or is it blindingly obvious
(only not to me) how to do this with a kernel debugger?

This is different from the dump I get in a kernel panic, right?

A successfull & happy 2004 to you, too! :-)

andreas
- -- 
Andreas Bunten         |                       mailto:[email protected]
DFN-CERT GmbH          |             http://www.cert.dfn.de/team/bunten/
Heidenkampsweg 41      |                        Phone: +49(40)808077-555
D-20097 Hamburg        |                          FAX: +49(40)808077-556
Germany	               |          PGP-Key: finger [email protected]
PGP-Key fingerprint  =  25 E9 A6 DD 15 6C 09 70  9D 05 10 2B C7 AB C2 31

-----BEGIN PGP SIGNATURE-----
Version: 2.6.2i

iQEVAgUBP/lUjygU04YpslABAQEKjwf+KHGZXXDWh6HOp62V+7tkBuI0OLSmFeqF
YUOXrZ6/jkE9Rj9ZpEEncPcE++d7Visokwc9bErlaYUeCmuVpFAqDlx2OyXbLPFC
qHi7Aq5S1+nA8JXeNyG0dgSs8xy/V4GLMw5SPpWouoW0C5k9qEjSpszE2E4q+kYp
4YlnFL3z6UTa1xtdWfUG6LhbM7ygndiqeOMHXCN7/gaxMhXvhEWrn/SQHI5oRubn
yE7l6v8BJdAEgDAUAA2aiZ+zrqDfJkb8W+C6OnG7r//u2JNeE4EjgLFS/DDTbheh
skKTZ9fe5SgnXw8ErzxwfM37XqOrydEhCslhZtFMnJ3WNA/xGNSUEA==
=T3Ls
-----END PGP SIGNATURE-----