Honeypots mailing list archives

Re: Forensics DD RDA problems


From: "Chris Boubalos" <boubalos () md5sa com>
Date: Mon, 30 Jun 2003 18:55:37 +0300

Hi all,

On Fri, 27 Jun 2003, nina nina wrote:

Trying to setup RDA on a win2k machine:

1.  Use Fire CD to download and *.dd images
    a. boot.img is less than 1.44mg
    b. root.img is more than 4mg

2.  DD both images but root.img.dd is of course still large

The problem is probably that the '.img' extention for the floppy image files confuses some browsers.

I just changed them to .bin
so if you try again you will probably get the files ok ( they are both less than 1.44MB )

4.  Is it possible to setup rda on win2k
rda client will only run on linux, but rda server can be ported to win32 in order to have something like:
 - boot source machine with linux and rda client
 - get data on a windows with rda server 
 - ready to analyse

the main reason for a win32 rda server is that linux cant write safely on an NTFS, so
if you get a big image you are forced to use 'span' cuz of the fat32 max file size limit.

I already wrote a test version of rda server for win32, but i dont think it'll be ready before summer vac.. :)

P.S. i just changed the extention and didnt check how every browser reacts..
  -  in case problems continue please let me know.

___________________
Chris Boubalos
Security & Forensics Team Leader
MD5 S.A.
boubalos () md5sa com
www.md5sa.com


Current thread: