Re: decoding konq_history
Michael Bond <[email protected]> Sun, 18 Mar 2007 02:22:01 -0400
| Newsgroups | gmane.org.user-groups.linux.morlug |
|---|---|
| Message-ID | <[email protected]> |
--===============1155500507== Content-Type: multipart/alternative; boundary=Apple-Mail-2-470709761 --Apple-Mail-2-470709761 Content-Transfer-Encoding: 7bit Content-Type: text/plain; charset=US-ASCII; delsp=yes; format=flowed To make sure i understand the problem. 1) You will have some sort of disk image that you are going to mount on your local file system? 2) You have to look at konq_hist to see where the 'bad guy' visited 3) This is for ... which class? While morlug is a great resource for questions like this, it sounds like this is for homework. As such, i really don't think anyone should (or will) provide a direct answer for you. What dave riggs suggested is correct: The first link provides this (click the link :-P ) http://lists.kde.org/?l=kfm-devel&m=106867941008409&w=2 Basically, read the documentation and write a script that reads in the file (as binary data) and converts it to plain text. There are a good number of references on the internet to handle the task in the language of your choosing. Personally I'd do it in perl or python, both handle this type of task very well. If this is NOT for a class of some sort and you actually had a 'bad guy' on your box, i suggest talking with one of the security experts on the list. Mike. [email protected] On Mar 17, 2007, at 8:55 PM, Nick Newman wrote: > Thanks for the quick response... I found that link earlier, but it > won't work for what I'm trying to do (forensic analysis of a Linux > box). I'm going to have an image of a Linux OS and will have to > analyze konq_history to see where the bad guy went and at what time > he went there. Any other ideas? > > On 3/18/07, David A. Riggs <[email protected]> wrote: > On 3/17/07, Nick Newman <[email protected]> wrote: > > I'm trying to find a way to decode the binary konq_history file, > which > > stores the history for Konqueror. Is there any easy way > (preferrably via > > some program) to convert that file to plain text? > > > > Type "konq_history" into Google, hit "I'm feeling lucky"... seriously. > > - DR > > -- > David A. Riggs < [email protected]> > _______________________________________________ > Morlug mailing list > [email protected] > http://mailman.morlug.org/mailman/listinfo/morlug > > > > -- > "Love all, trust a few, do wrong to none." -- William Shakespeare > _______________________________________________ > Morlug mailing list > [email protected] > http://mailman.morlug.org/mailman/listinfo/morlug --Apple-Mail-2-470709761 Content-Transfer-Encoding: quoted-printable Content-Type: text/html; charset=ISO-8859-1 <HTML><BODY style=3D"word-wrap: break-word; -khtml-nbsp-mode: space; = -khtml-line-break: after-white-space; "><DIV><BR = class=3D"khtml-block-placeholder"></DIV><DIV>To make sure i understand = the problem.</DIV><DIV><BR class=3D"khtml-block-placeholder"></DIV><DIV>1)= You will have some sort of disk image that you are going to mount on = your local file system?</DIV><DIV>2) You have to look at konq_hist to = see where the 'bad guy' visited</DIV><DIV>3) This is for ... which = class?</DIV><DIV><BR class=3D"khtml-block-placeholder"></DIV><DIV>While = morlug is a great resource for questions like this, it sounds like this = is for homework. As such, i really don't think anyone should (or will) = provide a direct answer for you. What dave riggs suggested is = correct:</DIV><DIV><BR class=3D"khtml-block-placeholder"></DIV><DIV>The = first link provides this (click the link :-P )</DIV><DIV><A = href=3D"http://lists.kde.org/?l=3Dkfm-devel&m=3D106867941008409&w=3D2">htt= p://lists.kde.org/?l=3Dkfm-devel&m=3D106867941008409&w=3D2</A></DI= V><DIV><BR class=3D"khtml-block-placeholder"></DIV><DIV>Basically, read = the documentation and write a script that reads in the file (as binary = data) and converts it to plain text.=A0</DIV><DIV><BR = class=3D"khtml-block-placeholder"></DIV><DIV>There are a good number of = references on the internet to handle the task in the language of your = choosing. Personally I'd do it in perl or python, both handle this type = of task very well.=A0</DIV><DIV><BR = class=3D"khtml-block-placeholder"></DIV><DIV>If this is NOT for a class = of some sort and you actually had a 'bad guy' on your box, i suggest = talking with one of the security experts on the list.=A0</DIV><DIV><BR = class=3D"khtml-block-placeholder"></DIV><DIV>Mike.</DIV><DIV><A = href=3D"mailto:[email protected]">[email protected]</A></DIV><= DIV><BR class=3D"khtml-block-placeholder"></DIV><BR><DIV><DIV>On Mar 17, = 2007, at 8:55 PM, Nick Newman wrote:</DIV><BR = class=3D"Apple-interchange-newline"><BLOCKQUOTE type=3D"cite">Thanks for = the quick response... I found that link earlier, but it won't work for = what I'm trying to do (forensic analysis of a Linux box).=A0 I'm going = to have an image of a Linux OS and will have to analyze konq_history to = see where the bad guy went and at what time he went there.=A0 Any other = ideas? <BR><BR><DIV><SPAN class=3D"gmail_quote">On 3/18/07, <B = class=3D"gmail_sendername">David A. Riggs</B> <<A = href=3D"mailto:[email protected]">[email protected]</A>> = wrote:</SPAN><BLOCKQUOTE class=3D"gmail_quote" style=3D"border-left: 1px = solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: = 1ex;"> On 3/17/07, Nick Newman <<A = href=3D"mailto:[email protected]">[email protected]<= /A>> wrote:<BR>> I'm trying to find a way to decode the binary = konq_history file, which<BR>> stores the history for Konqueror.=A0=A0Is= there any easy way (preferrably via <BR>> some program) to convert = that file to plain text?<BR>><BR><BR>Type "konq_history" into Google, = hit "I'm feeling lucky"... seriously.<BR><BR>- DR<BR><BR>--<BR>David A. = Riggs <<A href=3D"mailto:[email protected]"> = [email protected]</A>><BR>_______________________________________= ________<BR>Morlug mailing list<BR><A = href=3D"mailto:[email protected]">[email protected]</A><BR= ><A href=3D"http://mailman.morlug.org/mailman/listinfo/morlug"> = http://mailman.morlug.org/mailman/listinfo/morlug</A><BR></BLOCKQUOTE></DI= V><BR><BR clear=3D"all"><BR>-- <BR>"Love all, trust a few, do wrong to = none." -- William Shakespeare<DIV style=3D"margin-top: 0px; = margin-right: 0px; margin-bottom: 0px; margin-left: 0px; = ">_______________________________________________</DIV><DIV = style=3D"margin-top: 0px; margin-right: 0px; margin-bottom: 0px; = margin-left: 0px; ">Morlug mailing list</DIV><DIV style=3D"margin-top: = 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; "><A = href=3D"mailto:[email protected]">[email protected]</A></D= IV><DIV style=3D"margin-top: 0px; margin-right: 0px; margin-bottom: 0px; = margin-left: 0px; "><A = href=3D"http://mailman.morlug.org/mailman/listinfo/morlug">http://mailman.= morlug.org/mailman/listinfo/morlug</A></DIV> = </BLOCKQUOTE></DIV><BR><DIV> <SPAN class=3D"Apple-style-span" = style=3D"border-collapse: separate; border-spacing: 0px 0px; color: = rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: = normal; font-variant: normal; font-weight: normal; letter-spacing: = normal; line-height: normal; text-align: auto; = -khtml-text-decorations-in-effect: none; text-indent: 0px; = -apple-text-size-adjust: auto; text-transform: none; orphans: 2; = white-space: normal; widows: 2; word-spacing: 0px; "><SPAN = class=3D"Apple-style-span" style=3D"border-collapse: separate; = border-spacing: 0px 0px; color: rgb(0, 0, 0); font-family: Helvetica; = font-size: 12px; font-style: normal; font-variant: normal; font-weight: = normal; letter-spacing: normal; line-height: normal; text-align: auto; = -khtml-text-decorations-in-effect: none; text-indent: 0px; = -apple-text-size-adjust: auto; text-transform: none; orphans: 2; = white-space: normal; widows: 2; word-spacing: 0px; "><DIV><BR = class=3D"khtml-block-placeholder"></DIV><DIV><BR = class=3D"khtml-block-placeholder"></DIV><DIV><BR = class=3D"khtml-block-placeholder"></DIV><BR = class=3D"Apple-interchange-newline"></SPAN></SPAN> = </DIV><BR></BODY></HTML>= --Apple-Mail-2-470709761-- --===============1155500507== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Morlug mailing list [email protected] http://mailman.morlug.org/mailman/listinfo/morlug --===============1155500507==--