Honeypots mailing list archives

RE: Forensics DD RDA problems


From: "Mark E. Donaldson" <markee () bandwidthco com>
Date: Mon, 30 Jun 2003 21:31:15 -0700

You will need to burn the image onto a CD ROM and boot from the CD.  IF you
are interested in using netcat, there is an excellent paper from Foundstone
on this:
http://www.foundstone.com/pdf/ir-primer.pdf

-----Original Message-----
From: nina nina [mailto:n_joiner () hotpop com]
Sent: Friday, June 27, 2003 7:51 AM
To: honeypots () securityfocus com
Subject: Forensics DD RDA problems




Trying to setup RDA on a win2k machine:

1.  Use Fire CD to download and *.dd images
    a. boot.img is less than 1.44mg
    b. root.img is more than 4mg

2.  DD both images but root.img.dd is of course still large

3.  How do I get the image on a bootable floppy?
4.  Is it possible to setup rda on win2k

My ultimate objective is to use my forensics workstation and connect to
network machines to copy images and analyze.

I've read RDA and looked for posts but to no luck, I've decided to post.

What about nc or crypcat to connect to a remote machine?



Current thread: