Re: P2V - Live Forensics

[email protected] Fri, 25 Feb 2011 19:51:58 -0500
Newsgroups gmane.comp.security.forensics
Message-ID <7239.1298681518@localhost>
--==_Exmh_1298681518_5059P
Content-Type: text/plain; charset=us-ascii

On Mon, 21 Feb 2011 03:40:51 GMT, [email protected] said:
> DD on a live system, using netcat (both exist for windows), will allow you to
> image to a separate system over the network.

Been there, done that, but only on machines I controlled enough to be assured
it was essentially a quiesced system, and not in a forensics mode.  What are
people doing to deal with filesystem skew caused by activity during the hour or
two it can take to image over the network?  It's one thing to lose a few 'last
accessed' times on files that were touched after they were copied, it's
something else when the resulting filesystem won't even fsck or chkdisk
properly because something major changed during the imaging.

This is particularly important if you're trying to be stealthy and image a
system that's being used - even innocent actions like renaming folders can
cause issues with the resulting image.


--==_Exmh_1298681518_5059P
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)
Comment: Exmh version 2.5 07/13/2001

iD8DBQFNaE6ucC3lWbTT17ARAm0OAJ9Jt+sY+uUEhs7Rb/f9lpPV8gudUQCgksV+
hXguDOPRwBU4ylDpYJci6rQ=
=9II+
-----END PGP SIGNATURE-----

--==_Exmh_1298681518_5059P--