General Discussion: Facebook Profile Saver
Thanks for the replies. I am going to give FFT a whirl. This was not for an investigation. I wanted to save a friend who passed away's profile in case it was closed, etc. I am still friends with this...
View ArticleEducation and Training: BEST UNIVERSITIES FOR COMPUTING FORENSIC IN UK?
I'll chip in here too, similar to the previous poster im currently almost half way through my MSc Advanced Security & Digital Forensics @ Edinburgh Napier Uni. I did quite a bit of research before...
View ArticleMobile Phone Forensics: Galaxy S3 Arrrghhh!!
Tootypeg did you do finally physical acquisition of Galaxy S III ? What was the problem in XRY ? How did you resolve your problem with this phone ? What version of XRY did you use ?
View ArticleEducation and Training: MSc in Digital Forensics (leading uni's)???
Someone asked about the UK programmes & I just replied to that one, that is here: UK Masters in Digital Forensics However, the below is essentially my reply to that 1. v1nny.kum4r wrote: I'll chip...
View ArticleMobile Phone Forensics: Change in Hash values
The first thing I would do would be a binary compare of the two files. From DOS c:\fc /b <file1> <file2> You can see the size of the difference. If it is just a few bytes you might...
View ArticleForensic Software: Tableau Encase Acqusition problem
Pixff wrote: The company has an Old Tableu TD1 and Encase 6 that we used to duplicate an external 1TB USB drive after removing the case using fat32 and splitting the clone into several E01 files. We...
View ArticleForensic Hardware: TD3 Performance
I would do some tests without compression, and without hashing. Both can require intensive processing. With slow hardware, this processing time might be masked by the drive speed. With fast drives, the...
View ArticleForensic Software: mft2csv - NTFS systemfile extracter and $MFT decoder
All NTFS tools available at my accounts at github/code.google updated to also support 4096 byte sized MFT records.
View ArticleGeneral Discussion: Even more SetMace
joakims wrote: Now I think the project has reached a dead end, unless someone else wants to take it further into handling the raw structures of shadow copies.. And then a few more fixes was done, to...
View ArticleMobile Phone Forensics: Change in Hash values
If the hash values are different, so are the files - OR - you are not hashing what you think you are hashing - OR - you are testing the wrong files (eg same name different directory is my common...
View ArticleForensic Hardware: TD3 Performance
If compression cannot be turned off you will want to 'play' with the data on you input drive. Is there a difference if you blank your input drive and do a timing test, and then fill it with videos (or...
View ArticleGeneral Discussion: Write Blocker script issue
Thank you very much for all the info thefuf. I didn't expect the same author to answer my questions. I really appreciated.
View ArticleMobile Phone Forensics: Galaxy S III mini GT - I8190N
Dear colleagues. Do you know is it possible to get physical acquisition of Galaxy S III mini GT - I8190N in XRY 6.10 or EnCase 7.09 ? Is it required to place the handset into download mode before...
View ArticleEducation and Training: Best certs for UK
bitznpcz wrote: Most of the ones I have seen such as SANS 408 and CCE seem to cover US law rather than the UK legal system. CCE -- as far as I remember it -- may have some questions on US law, but not...
View ArticleMobile Phone Forensics: Mount /data partition read only?
But I am possible to mount /system, the issue is with /data.
View ArticleMobile Phone Forensics: Garmin Forerunner Download
Does the memory mount when the device is attached to a computer. In the past I have had sat nav systems off bikes, imaged them first then 'synced' it with the specific garmin software for that device...
View ArticleMobile Phone Forensics: LG800 cell phone
Why JTAG specifically? Are you trying to get deleted data from the device?
View Article