<?xml version="1.0" encoding="UTF-8" ?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>ForensicAnalysis at Yahoo! Groups</title>
    <link>http://tech.groups.yahoo.com/group/ForensicAnalysis/</link>
    <description>Forensic Analysis</description>

    <item>
      <title>FAU-1.3.0.2390 released for evaluation and testing.</title>
      <pubDate>Mon, 03 Aug 2009 23:10:18 GMT</pubDate>
      <dc:creator>rossetoecioccolato</dc:creator>
      <link>http://tech.groups.yahoo.com/group/ForensicAnalysis/message/91</link>
      <guid isPermaLink="true">http://tech.groups.yahoo.com/group/ForensicAnalysis/message/91</guid>
      <description>FAU-1.3.0.2390 is released for evaluation and testing and may be downloaded from</description>
    </item>
    <item>
      <title>Vmware ThinApp/Thinstall Is it Good or Bad?</title>
      <pubDate>Sun, 13 Jul 2008 21:50:02 GMT</pubDate>
      <dc:creator>nitinceh</dc:creator>
      <link>http://tech.groups.yahoo.com/group/ForensicAnalysis/message/90</link>
      <guid isPermaLink="true">http://tech.groups.yahoo.com/group/ForensicAnalysis/message/90</guid>
      <description>Hi all, I found this new tool released by VMware, IS it good or Bad, from the forensics and IT-Security point of view? Need your comments! Read on! Application</description>
    </item>
    <item>
      <title>Re: Cofee -- Analysis of the Forensic Thumb drive</title>
      <pubDate>Wed, 28 May 2008 19:13:08 GMT</pubDate>
      <dc:creator>Greg Kelley</dc:creator>
      <link>http://tech.groups.yahoo.com/group/ForensicAnalysis/message/89</link>
      <guid isPermaLink="true">http://tech.groups.yahoo.com/group/ForensicAnalysis/message/89</guid>
      <description>I am not aware of what it does specifically, just aware of what it is at a higher level. -Greg ... From: ForensicAnalysis@yahoogroups.com </description>
    </item>
    <item>
      <title>Re: Cofee -- Analysis of the Forensic Thumb drive</title>
      <pubDate>Wed, 28 May 2008 19:07:14 GMT</pubDate>
      <dc:creator>nitinceh</dc:creator>
      <link>http://tech.groups.yahoo.com/group/ForensicAnalysis/message/88</link>
      <guid isPermaLink="true">http://tech.groups.yahoo.com/group/ForensicAnalysis/message/88</guid>
      <description>... Hello Greg, Thanks for your reply, I just wanted to know more insight of how does it crack the password&#39;s if the Desktop/Workstation is Locked. Is it done</description>
    </item>
    <item>
      <title>Re: Cofee -- Analysis of the Forensic Thumb drive</title>
      <pubDate>Tue, 27 May 2008 13:30:24 GMT</pubDate>
      <dc:creator>Greg Kelley</dc:creator>
      <link>http://tech.groups.yahoo.com/group/ForensicAnalysis/message/87</link>
      <guid isPermaLink="true">http://tech.groups.yahoo.com/group/ForensicAnalysis/message/87</guid>
      <description>From what I have learned, there is nothing &quot;super secret&quot; about this USB drive tool.  All they did was create some scripts to automate the tools and processes</description>
    </item>
    <item>
      <title>Re: Cofee -- Analysis of the Forensic Thumb drive</title>
      <pubDate>Sun, 25 May 2008 09:52:45 GMT</pubDate>
      <dc:creator>nitinceh</dc:creator>
      <link>http://tech.groups.yahoo.com/group/ForensicAnalysis/message/86</link>
      <guid isPermaLink="true">http://tech.groups.yahoo.com/group/ForensicAnalysis/message/86</guid>
      <description>... Thanks rossetoecioccolato, I will do that, however i just thought may be from our group someone would have tried this. I am only concerned with the</description>
    </item>
    <item>
      <title>Re: Cofee -- Analysis of the Forensic Thumb drive</title>
      <pubDate>Sun, 25 May 2008 05:15:36 GMT</pubDate>
      <dc:creator>rossetoecioccolato</dc:creator>
      <link>http://tech.groups.yahoo.com/group/ForensicAnalysis/message/85</link>
      <guid isPermaLink="true">http://tech.groups.yahoo.com/group/ForensicAnalysis/message/85</guid>
      <description>Nitin, Why don&#39;t you try contacting the author directly. His name is Anthony Fung.  You will find his email address towards the middle of this page:</description>
    </item>
    <item>
      <title>Cofee -- Analysis of the Forensic Thumb drive</title>
      <pubDate>Sat, 24 May 2008 10:42:15 GMT</pubDate>
      <dc:creator>nitinceh</dc:creator>
      <link>http://tech.groups.yahoo.com/group/ForensicAnalysis/message/84</link>
      <guid isPermaLink="true">http://tech.groups.yahoo.com/group/ForensicAnalysis/message/84</guid>
      <description>Hi All, I have just seen this on sites with the content on Microsoft giving away a thumb drive to LE Tech agents to acquire evidence from a live computer. this</description>
    </item>
    <item>
      <title>Re: dcfldd and bad sectors</title>
      <pubDate>Sat, 24 May 2008 03:58:13 GMT</pubDate>
      <dc:creator>rossetoecioccolato</dc:creator>
      <link>http://tech.groups.yahoo.com/group/ForensicAnalysis/message/83</link>
      <guid isPermaLink="true">http://tech.groups.yahoo.com/group/ForensicAnalysis/message/83</guid>
      <description>... [...] ... DDrescue with &#39;-d&#39; uses the O_DIRECT flag (unbuffered IO) that was introduced with Linux 2.4 kernels (google for &quot;O_DIRECT&quot;): int do_rescue() { </description>
    </item>
    <item>
      <title>dcfldd and bad sectors</title>
      <pubDate>Fri, 23 May 2008 19:55:58 GMT</pubDate>
      <dc:creator>rossetoecioccolato</dc:creator>
      <link>http://tech.groups.yahoo.com/group/ForensicAnalysis/message/82</link>
      <guid isPermaLink="true">http://tech.groups.yahoo.com/group/ForensicAnalysis/message/82</guid>
      <description>The following question originally arose over on another list: &quot;Open source tools such as DCFLdd v1.3.4-1 can usually recover all data, with exception of the</description>
    </item>
    <item>
      <title>FAU-1.3.0.2364(beta1) released for evaluation and testing.</title>
      <pubDate>Thu, 15 May 2008 03:19:29 GMT</pubDate>
      <dc:creator>rossetoecioccolato</dc:creator>
      <link>http://tech.groups.yahoo.com/group/ForensicAnalysis/message/81</link>
      <guid isPermaLink="true">http://tech.groups.yahoo.com/group/ForensicAnalysis/message/81</guid>
      <description>FAU-1.3.0.2364(beta1) has been released for evaluation and testing and may be downloaded from http://www.gmgsystemsinc.com/fau/b9b651b7- </description>
    </item>
    <item>
      <title>Re: Vista Restore Points and Recovery</title>
      <pubDate>Tue, 15 Apr 2008 14:34:24 GMT</pubDate>
      <dc:creator>Eric Klink</dc:creator>
      <link>http://tech.groups.yahoo.com/group/ForensicAnalysis/message/80</link>
      <guid isPermaLink="true">http://tech.groups.yahoo.com/group/ForensicAnalysis/message/80</guid>
      <description>Yes, you are right. But my range of dates was nicely narrow. I seized the computer on Dec 7 2007. I had a report of pics as seen by a witness on Nov 28 2007.</description>
    </item>
    <item>
      <title>Re: Vista Restore Points and Recovery</title>
      <pubDate>Tue, 15 Apr 2008 13:17:32 GMT</pubDate>
      <dc:creator>Greg Kelley</dc:creator>
      <link>http://tech.groups.yahoo.com/group/ForensicAnalysis/message/79</link>
      <guid isPermaLink="true">http://tech.groups.yahoo.com/group/ForensicAnalysis/message/79</guid>
      <description>Eric, Correct me if I am wrong, but I believe EXIF data is placed inside of a file by the camera that creates the files and/or the application you use to</description>
    </item>
    <item>
      <title>Re: Vista Restore Points and Recovery</title>
      <pubDate>Mon, 14 Apr 2008 19:57:27 GMT</pubDate>
      <dc:creator>Eric Klinkowski</dc:creator>
      <link>http://tech.groups.yahoo.com/group/ForensicAnalysis/message/78</link>
      <guid isPermaLink="true">http://tech.groups.yahoo.com/group/ForensicAnalysis/message/78</guid>
      <description>I ended up making my case off of using EXIF data as evidence in this case. It was a child pornography case. I was unable to retrieve any MAC (modified accessed</description>
    </item>
    <item>
      <title>Re: Vista Restore Points and Recovery</title>
      <pubDate>Tue, 11 Mar 2008 18:55:44 GMT</pubDate>
      <dc:creator>Eric Klink</dc:creator>
      <link>http://tech.groups.yahoo.com/group/ForensicAnalysis/message/77</link>
      <guid isPermaLink="true">http://tech.groups.yahoo.com/group/ForensicAnalysis/message/77</guid>
      <description>ok thanks, that makes more sense. Greg Kelley &lt;gkelley@...&gt; wrote: You  have to go beyond the index.dat files.  NetAnalysis provides a utility that</description>
    </item>

  </channel>
</rss>
<!-- wr2.grp.sp2.yahoo.com uncompressed/chunked Thu Dec 31 12:19:33 PST 2009 -->
