亚洲欧美第一页_禁久久精品乱码_粉嫩av一区二区三区免费野_久草精品视频

? 歡迎來到蟲蟲下載站! | ?? 資源下載 ?? 資源專輯 ?? 關(guān)于我們
? 蟲蟲下載站

?? ref_fs.txt

?? linux下開發(fā)的針對(duì)所有磁盤的數(shù)據(jù)恢復(fù)的源碼
?? TXT
字號(hào):
                    File System Analysis Techniques                     Sleuth Kit Reference Document                        http://www.sleuthkit.org                            Brian Carrier                        Last Updated: July 2005INTRODUCTION=======================================================================Currently, evidence is most frequently found in the file system.This is because it is non-volatile and remnants of deleted filescan typically be found.  This file will help one to use the low-leveltools in The Sleuth Kit for a forensic analysis.This document is organized into small scenarios, which provideexamples of how to use The Sleuth Kit.  Most of these functionsare automated with Autopsy, but they are here for reference andeducation.      http://www.sleuthkit.org/autopsyThe techniques used here apply to both UNIX and Windows file systems.TIME LINE=======================================================================The steps from the timeline Sleuth Kit Implementation Notes arefollowed (using both ils and fls) and you notice some interestingactivity from unallocated inodes, namely MFT Entry 5035 from imagec_drive.dd.  To display the contents of this file, use "icat":    # icat images/c_drive.dd 5035 | lessNOTE: To prevent your terminal from getting messed up, pipe alloutput of "icat" through a pager like "less".SEARCH=======================================================================In this scenario, we will search the unallocated space of the"wd0e.dd" image for the string "abcdefg".  The first step is toextract the unallocated disk units using the "blkls" tool (as thisis an FFS image, the addressable units are fragments).    # blkls images/wd0e.dd > output/wd0e.blklsNext, use the UNIX strings(1) utility to extract all of the ASCIIstrings in the file of unallocated data.  If we are only going to besearching for one string, we may not need to do this.  If we are goingto be searching for many strings, then this is faster.  Use the '-t d'flags with "strings" to print the byte offset that the string was found.    # strings -t d output/wd0e.blkls > output/wd0e.blkls.strUse the UNIX grep(1) utility to search the strings file.      # grep "abcdefg" output/wd0e.blkls.str | less    10389739: abcdefgWe notice that the string is located at byte 10389739.  Next,determine what fragment.  To do this, we use the 'fsstat' tool:    # fsstat openbsd images/wd0e.dd	<...>    CONTENT-DATA INFORMATION    --------------------------------------------    Fragment Range: 0 - 266079    Block Size: 8192    Fragment Size: 1024This shows us that each fragment is 1024 bytes long.  Using acalculator, we find that byte 10389739 divided by 1024 is 10146(and change).  This means that the string "abcdefg" is located infragment 10146 of the "blkls" generated file.  This does not reallyhelp us because the blkls image is not a real file system.  To viewthe full fragment from the blkls image, we can use dd:    # dd if=images/wd0e.dd bs=1024 skip=10146 count=1 | lessNext, we will identify where this fragment is in the original image.The "blkcalc" tool will be used for this.  "blkcalc" will return the"address" in the original image when given the "address" in theblkls generated image.  (NOTE, this is currently kind of slow).  The'-u' flag shows that we are giving it an blkls address.  If the '-d'flag is given, then we are giving it a dd address and it willidentify the blkls address.    # blkcalc -u 10146 images/wd0e.dd    59382Therefore, the string "abcdefg" is located in fragment 59382.  To viewthe contents of this fragment, we can use "blkcat".    # blkcat images/wd0e.dd 59382 | lessTo make more sense of this, let us identify if there is a meta datastructure that still has a pointer to this fragment.  This is achievedusing "ifind".  The '-a' argument means to find all occurrences.  # ifind -a images/wd0e.dd 59382  493Inode 493 has a pointer to fragment 59382.  Let us get more informationabout inode 493, using "istat".    # istat images/wd0e.dd 493	inode: 493	Not Allocated	uid / gid: 1000 / 1000	mode: rw-------	size: 92	num of links: 1	Modified:       08.10.2001 17:09:49     (GMT+0)	Accessed:       08.10.2001 17:09:58     (GMT+0)	Changed:        08.10.2001 17:09:49     (GMT+0)	Direct Blocks:	  59382Next, let us find out if there is a file that is still associated withthis (unallocated) inode.  This is done using "ffind".    # ffind -a images/wd0e.dd 493	* /dev/.123456The leading '*' identifies the file as deleted.  Therefore, at one point,the file '/dev/.123456' allocated inode 493, which allocated fragment59382, which contained the string "abcdefg".If "ffind" returned with more than file that had allocated inode 493,it means that either both were hard-links to the same file or that onefile (chicken) allocated the inode, it was deleted, a second file (egg)allocated it, and then it was deleted.  The string belongs to the secondfile, but it is difficult to determine which came first.  On the otherhand, if "ffind" returns with two entries where one deleted and one not,then the string belongs to the non-deleted file.As previously mentioned, Autopsy will do all of this for you whenyou do a keyword search of unallocated space.  DELETED CONTENT=======================================================================To view all of the deleted file names in an image, use the "fls" tool.For all deleted files, use the '-r' flag for recursive and '-d' flagfor deleted.    # fls -rd images/hda9.dd | less    d/d * 232: 	/TEMP-823450    r/d * 293: 	/TEMP-131100	This shows us the full path that the deleted files are located.  On somesystems, such as Windows NTFS, the file content may be recovered(depending on how much system activity has occurred).  On othersystems, such as Solaris UFS and Linux Ext3, deleted files can notbe easily recovered.   The number at the beginning of the line isthe inode number.  The '*' shows that it is deleted and the 'd' and'r' show the type (directory and file).  The first letter identifiesthe directory entry type value (which does not exist in all filesystem types) and the second letter is the type according to theinode.  In most cases these should be the same, but it may not fordeleted files if the inode has been reallocated to a file of adifferent type.  If we do an "istat" on the directory (232) we willnotice that the size is 0.    # istat images/hda9.dd 232	inode: 232	Not Allocated	uid / gid: 0 / 0	mode: rwxr-xr-x	size: 0	num of links: 0	Modified:       08.23.2001 21:52:33     (GMT+0)	Accessed:       08.23.2001 23:05:39     (GMT+0)	Changed:        08.23.2001 21:52:33     (GMT+0)	Deleted:        08.23.2001 23:05:39     (GMT+0)	Direct Blocks:Linux does this to all of its deleted directories.  It should alsobe observed that no block addresses are shown in the "istat" output.This is because the size is 0 and the program thinks that the addressis bogus.  Using the '-b' option of "istat", we can force it tooutput the block address.  With Linux Ext3, the block pointers wouldbe 0, but Linux Ext2 kept the old addresses.    # istat -b 2 images/hda9.dd 232	inode: 232	Not Allocated	uid / gid: 0 / 0	mode: rwxr-xr-x	size: 0	num of links: 0	Modified:       08.23.2001 21:52:33     (GMT+0)	Accessed:       08.23.2001 23:05:39     (GMT+0)	Changed:        08.23.2001 21:52:33     (GMT+0)	Deleted:        08.23.2001 23:05:39     (GMT+0)	Direct Blocks:	  388 0Now we can examine the contents of block 388 and see the filenames that were in that directory:    # blkcat -h images/hda9.dd 388 | lessMANUAL UNIX FILE RECOVERY=======================================================================A UFS/FFS or EXT2FS/EXT3FS file system is organized into groups.Each group has its own inodes and blocks to store data in.  Whena new file is created, it is given an inode in the same group thatthe parent directory inode is in (if there are still inodesavailable).  When a new directory is created, it is given an inodein a new group.  An inode allocates blocks from the same group thatits inode is in.When recovering a file from one UFS or EXTxFS, the group layoutcan be used.  When a deleted file is found with 'fls', notice theinode of the parent directory:    # fls -r images/hda1.dd	d/d 30789:      doc    + r/r * 0:    doc/.a/ssh.tar    + r/r 30792:    doc/.a/install	<...>We want to recover the 'ssh.tar' file and notice that the parentdirectory is 30789 and the deleted file has a cleared inode pointer.To identify the group that it is in, the 'fsstat' tool is used:    # fsstat images/hda1.dd    FILE SYSTEM INFORMATION    --------------------------------------------    File System Type: EXT3FS	<...>    Group: 0:      Inode Range: 1 - 15392      Block Range: 0 - 32767        Super Block: 0 - 0        Group Descriptor Table: 1 - 1        Data bitmap: 2 - 2        Inode bitmap: 3 - 3        Inode Table: 4 - 484        Data Blocks: 485 - 32767    Group: 1:      Inode Range: 15393 - 30784      Block Range: 32768 - 65535        Super Block: 32768 - 32768        Group Descriptor Table: 32769 - 32769        Data bitmap: 32770 - 32770        Inode bitmap: 32771 - 32771        Inode Table: 32772 - 33252        Data Blocks: 33253 - 65535    Group: 2:      Inode Range: 30785 - 46176      Block Range: 65536 - 98303        Data bitmap: 65536 - 65536        Inode bitmap: 65537 - 65537        Inode Table: 65540 - 66020        Data Blocks: 65538 - 65539, 66021 - 98303    <...>The inode is in the range of inode addresses for group 1.  To searchfor the deleted file, we extract the unallocated space using 'blkls':    # blkls images/hda1.dd 32768-65535 > output/hda1-grp1.blklsIf we wanted to extract all of the data for the group, we coulduse 'dd':    # dd if=images/hda1.dd of=output/hda1-grp1.dd bs=4096 skip=32768 \      count=32767Where, the fragment size is 4096 (which can also be found in the'fsstat' output).  Either of these images can then be analyze forkeywords or using other data carving tools such as 'foremost'.This process allows one to reduce the amount of data that must beanalyzed.    http://foremost.sourceforge.net-----------------------------------------------------------------------Send documentation updates to: <doc-updates at sleuthkit dot org>Copyright (c) 2002-2005 by Brian Carrier.  All Rights Reserved

?? 快捷鍵說明

復(fù)制代碼 Ctrl + C
搜索代碼 Ctrl + F
全屏模式 F11
切換主題 Ctrl + Shift + D
顯示快捷鍵 ?
增大字號(hào) Ctrl + =
減小字號(hào) Ctrl + -
亚洲欧美第一页_禁久久精品乱码_粉嫩av一区二区三区免费野_久草精品视频
日韩二区三区四区| 日韩一区在线免费观看| 色综合色综合色综合| 国产一区91精品张津瑜| 麻豆精品一区二区综合av| 亚洲最色的网站| 亚洲男人的天堂av| 最新欧美精品一区二区三区| 精品国产乱码久久久久久老虎| 欧美日韩1234| 欧美丰满嫩嫩电影| 欧美一区二区三级| 91精品国产高清一区二区三区| 欧美视频在线观看一区二区| 色婷婷久久久综合中文字幕 | 精一区二区三区| 日韩电影一二三区| 日韩电影在线看| 美日韩一区二区| 国产麻豆一精品一av一免费| 国内不卡的二区三区中文字幕| 狠狠狠色丁香婷婷综合久久五月| 精油按摩中文字幕久久| 国产精品一线二线三线精华| 国产精品主播直播| 一本到不卡精品视频在线观看| 一本久道久久综合中文字幕| 欧美日韩一区 二区 三区 久久精品| 91成人网在线| 欧美一区二区高清| 久久久久久免费网| 中文字幕一区二区三区在线播放| 亚洲男人的天堂av| 青青草国产成人99久久| 国产激情精品久久久第一区二区 | 久草中文综合在线| 国产成人一级电影| 91色porny蝌蚪| 91精品国产高清一区二区三区| 久久嫩草精品久久久久| 亚洲人妖av一区二区| 午夜精品久久久久久久| 国产suv精品一区二区6| 在线免费观看日本一区| 精品国产青草久久久久福利| 国产精品午夜久久| 日韩高清一级片| 9色porny自拍视频一区二区| 欧美日韩aaaaa| 国产精品全国免费观看高清 | 懂色av一区二区三区蜜臀| 色哟哟一区二区三区| 884aa四虎影成人精品一区| 亚洲国产精品二十页| 亚洲综合激情另类小说区| 国产酒店精品激情| 精品视频123区在线观看| 国产亚洲欧美日韩俺去了| 午夜视频一区在线观看| eeuss鲁片一区二区三区在线看| 欧美日韩精品一区视频| 国产精品天美传媒沈樵| 日韩和欧美一区二区| 一本色道久久加勒比精品| 91精品国产91久久综合桃花| 中文字幕在线不卡一区| 国产在线精品一区在线观看麻豆| 欧美无砖专区一中文字| 国产精品乱码一区二三区小蝌蚪| 麻豆视频观看网址久久| 欧美精品免费视频| 一区二区欧美在线观看| 色综合久久久久网| 亚洲国产精品成人久久综合一区 | 青青草原综合久久大伊人精品| 97成人超碰视| 国产精品传媒入口麻豆| 成人性生交大合| 欧美激情一区二区三区蜜桃视频 | 日韩精品在线一区| 免费久久精品视频| 日韩免费性生活视频播放| 奇米777欧美一区二区| 欧美唯美清纯偷拍| 午夜精品久久久久久| 911精品产国品一二三产区| 亚洲一区二区三区免费视频| 色综合久久综合| 亚洲一区二区三区爽爽爽爽爽| 在线一区二区三区四区五区| 一区二区三区日韩欧美| 欧洲国内综合视频| 午夜视频在线观看一区二区| 日韩一区二区中文字幕| 久久99热这里只有精品| 精品少妇一区二区| 国产麻豆一精品一av一免费| 国产欧美日韩麻豆91| 99天天综合性| 午夜一区二区三区在线观看| 777xxx欧美| 激情五月播播久久久精品| 国产欧美一区二区精品久导航| 国产精品影音先锋| 亚洲精品成人精品456| 欧美日韩一区二区三区高清| 久久精品久久综合| 欧美极品另类videosde| 在线视频国产一区| 免费精品视频在线| 国产日产欧产精品推荐色| 97精品电影院| 六月丁香综合在线视频| 国产蜜臀97一区二区三区| 一本大道久久精品懂色aⅴ| 日本欧美大码aⅴ在线播放| 国产目拍亚洲精品99久久精品| 色婷婷综合久久久| 久久草av在线| 亚洲欧美日韩电影| 欧美成人精品1314www| 成人精品视频一区| 日韩精品1区2区3区| 中文字幕日韩欧美一区二区三区| 在线精品视频一区二区| 国产综合色视频| 亚洲午夜在线电影| 久久久国产综合精品女国产盗摄| 99视频超级精品| 奇米精品一区二区三区在线观看| 亚洲欧洲av一区二区三区久久| 日韩一区二区在线看| 在线一区二区三区| 国产不卡视频一区| 美女脱光内衣内裤视频久久网站 | 国产曰批免费观看久久久| 亚洲人成影院在线观看| 精品国产亚洲在线| 欧美曰成人黄网| 91一区二区三区在线观看| 美女视频一区在线观看| 亚洲成av人片一区二区三区| 亚洲三级小视频| 久久综合色婷婷| 日韩午夜在线观看视频| 欧美丝袜自拍制服另类| 91一区二区在线| 成人黄色免费短视频| 久久精品免费看| 麻豆精品视频在线观看免费| 亚洲一区二区三区四区在线观看 | 欧美电影免费观看高清完整版在线| av影院午夜一区| 国产精品白丝jk白祙喷水网站 | 色8久久人人97超碰香蕉987| 国产成人aaa| 国产原创一区二区| 激情另类小说区图片区视频区| 丝袜美腿成人在线| 水蜜桃久久夜色精品一区的特点| 亚洲精品中文在线| 亚洲欧美视频在线观看| 一区二区三区自拍| 一区二区高清免费观看影视大全| 综合久久一区二区三区| 亚洲激情自拍偷拍| 亚洲欧美另类图片小说| 一区二区三区免费网站| 亚洲最大成人综合| 天堂影院一区二区| 午夜精品久久久久久久99樱桃| 婷婷综合五月天| 天堂一区二区在线| 另类小说图片综合网| 国产九色sp调教91| 国产一二精品视频| 99久久精品国产精品久久| 91免费看`日韩一区二区| 色美美综合视频| 欧美伦理影视网| 91精品国产欧美一区二区成人| 日韩欧美在线不卡| 久久精品日产第一区二区三区高清版| 精品电影一区二区三区| 欧美激情一区二区三区在线| **欧美大码日韩| 日韩成人av影视| 国产精品一区在线观看乱码| 91丨九色丨蝌蚪丨老版| 欧美日本一区二区三区| 欧美精品一区二区三区蜜臀| 国产精品精品国产色婷婷| 亚洲激情五月婷婷| 国产中文字幕一区| 91蜜桃视频在线| 精品精品国产高清一毛片一天堂| 国产精品嫩草影院com| 亚洲国产欧美另类丝袜| 国产v综合v亚洲欧| 在线成人小视频|