Re: memdump - UNIX memory dumper
Andreas Bunten <[email protected]> Mon, 5 Jan 2004 13:11:54 +0100 (MET)
| Newsgroups | gmane.comp.security.forensics.tct |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- On Thu, 1 Jan 2004, Wietse Venema wrote: (...) > What can you find in a system memory dump? Bits from the operating > system, from running processes, and from every file and directory > that has been accessed recently. Depending on the operating system > you may even find some information from deleted files and exited > processes, although that information tends to be short-lived. (...) This sounds very usefull! Are there tools or any help on how to extract these usefull bits from the dump? Like getting a list of processes and their allocated pages directly from the kernel structures ... Or is it blindingly obvious (only not to me) how to do this with a kernel debugger? This is different from the dump I get in a kernel panic, right? A successfull & happy 2004 to you, too! :-) andreas - -- Andreas Bunten | mailto:[email protected] DFN-CERT GmbH | http://www.cert.dfn.de/team/bunten/ Heidenkampsweg 41 | Phone: +49(40)808077-555 D-20097 Hamburg | FAX: +49(40)808077-556 Germany | PGP-Key: finger [email protected] PGP-Key fingerprint = 25 E9 A6 DD 15 6C 09 70 9D 05 10 2B C7 AB C2 31 -----BEGIN PGP SIGNATURE----- Version: 2.6.2i iQEVAgUBP/lUjygU04YpslABAQEKjwf+KHGZXXDWh6HOp62V+7tkBuI0OLSmFeqF YUOXrZ6/jkE9Rj9ZpEEncPcE++d7Visokwc9bErlaYUeCmuVpFAqDlx2OyXbLPFC qHi7Aq5S1+nA8JXeNyG0dgSs8xy/V4GLMw5SPpWouoW0C5k9qEjSpszE2E4q+kYp 4YlnFL3z6UTa1xtdWfUG6LhbM7ygndiqeOMHXCN7/gaxMhXvhEWrn/SQHI5oRubn yE7l6v8BJdAEgDAUAA2aiZ+zrqDfJkb8W+C6OnG7r//u2JNeE4EjgLFS/DDTbheh skKTZ9fe5SgnXw8ErzxwfM37XqOrydEhCslhZtFMnJ3WNA/xGNSUEA== =T3Ls -----END PGP SIGNATURE-----