Honeypots mailing list archives

preparing Honeypot hard drives


From: "Lefti" <lefti_99 () hotmail com>
Date: Sat, 16 Oct 2004 19:24:32 +0100

Hi all,

Is there a difference between running "fdisk c:" on a honeypot (booted from
a boot floppy) in order to destroy all the partitions on the hard drive, and
running "dd bs=1000k < /dev/zero > /dev/sda" ??

The fdisk command will be much easier to deliver because as far as I know,
the 'dd' command for win32 will only run within windows.  I'm try to prepare
my hard disk such that when it comes to doing forensics, I'm not picking up
data from old installations.

Many thanks,

Lefti


Current thread: