[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: raw disk access



In article <[🔎] 1041995302.6379.49.camel@cartman.veeev.net> viv@veeev.com writes:
>	i am looking for forensics tools that can be used in computer
>	crime investigations, and am particularly interesting in a tool
>	that provides raw drive (hard, floppy, CD, DVD, etc.) access in
>	order to create complete and accurate drive images.

Low level tools are no trick at all.  If you are root or root has given
you access (recomended), you can use any normal tools (dd, grep, perl)
on the appropriate /dev/hd* or /dev/sd* .

You can mount the filesystem read-only if you don't want to access
deleted files, etc.



-- 
Blars Blarson			blarson@blars.org
				http://www.blars.org/blars.html
"Text is a way we cheat time." -- Patrick Nielsen Hayden



Reply to: