<?xml version="1.0" encoding="UTF-8" ?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>linux_forensics at Yahoo! Groups</title>
    <link>http://tech.groups.yahoo.com/group/linux_forensics/</link>
    <description>linux_forensics</description>

    <item>
      <title>Caine 1.5 - Codename &quot;Shining&quot;</title>
      <pubDate>Wed, 18 Nov 2009 12:38:17 GMT</pubDate>
      <dc:creator>Nanni Bassetti</dc:creator>
      <link>http://tech.groups.yahoo.com/group/linux_forensics/message/3159</link>
      <guid isPermaLink="true">http://tech.groups.yahoo.com/group/linux_forensics/message/3159</guid>
      <description>Caine 1.5 is online! http://www.caine-live.net/ The Changelog is in home page. New tools, new manual, new web site, new graphics, new kernel. Thanks :-) ... </description>
    </item>
    <item>
      <title>Urgent Reply requested and guidline needed</title>
      <pubDate>Sun, 15 Nov 2009 11:18:05 GMT</pubDate>
      <dc:creator>santoshmtl</dc:creator>
      <link>http://tech.groups.yahoo.com/group/linux_forensics/message/3158</link>
      <guid isPermaLink="true">http://tech.groups.yahoo.com/group/linux_forensics/message/3158</guid>
      <description>Hello Friends, I am really new to Forensic field. I am doing Master of Engineering in Information Systems Security. I like this IT Security Field. Since, I am</description>
    </item>
    <item>
      <title>Caine 1.0 is online!</title>
      <pubDate>Thu, 29 Oct 2009 23:54:47 GMT</pubDate>
      <dc:creator>Nanni Bassetti</dc:creator>
      <link>http://tech.groups.yahoo.com/group/linux_forensics/message/3157</link>
      <guid isPermaLink="true">http://tech.groups.yahoo.com/group/linux_forensics/message/3157</guid>
      <description>Today was born Caine 1.0, new tools, new mounting policies (safer), new patch....enjoy it! http://www.caine-live.net/ bye ... Dott. Nanni Bassetti Consulente</description>
    </item>
    <item>
      <title>ssdeep hashset</title>
      <pubDate>Mon, 19 Oct 2009 21:07:20 GMT</pubDate>
      <dc:creator>Tony Rodrigues</dc:creator>
      <link>http://tech.groups.yahoo.com/group/linux_forensics/message/3156</link>
      <guid isPermaLink="true">http://tech.groups.yahoo.com/group/linux_forensics/message/3156</guid>
      <description>Hi, folks ! What ssdeep hashset do you use to sort/filter a forensic image ? NSRL doesn&#39;t have it, yeah ? []s -- Tony Rodrigues, CISSP, CFCP Forense</description>
    </item>
    <item>
      <title>Re: MS Office meta data</title>
      <pubDate>Mon, 12 Oct 2009 01:14:41 GMT</pubDate>
      <dc:creator>Simson Garfinkel</dc:creator>
      <link>http://tech.groups.yahoo.com/group/linux_forensics/message/3155</link>
      <guid isPermaLink="true">http://tech.groups.yahoo.com/group/linux_forensics/message/3155</guid>
      <description>I use libextractor for traditional MS Office files and custom-written tools for the XML-based file formats. You may also find this interesting: Garfinkel, S.,</description>
    </item>
    <item>
      <title>Re: MS Office meta data</title>
      <pubDate>Thu, 08 Oct 2009 23:49:19 GMT</pubDate>
      <dc:creator>Bob Kardell</dc:creator>
      <link>http://tech.groups.yahoo.com/group/linux_forensics/message/3154</link>
      <guid isPermaLink="true">http://tech.groups.yahoo.com/group/linux_forensics/message/3154</guid>
      <description>If you are into Perl programing, look at Harlan Carvey&#39;s Perl mod File::MSWord and see: http://windowsir.blogspot.com/2006/09/metadata-and-ediscovery.html you</description>
    </item>
    <item>
      <title>Re: MS Office meta data</title>
      <pubDate>Thu, 08 Oct 2009 23:24:58 GMT</pubDate>
      <dc:creator>Jeff Bryner</dc:creator>
      <link>http://tech.groups.yahoo.com/group/linux_forensics/message/3153</link>
      <guid isPermaLink="true">http://tech.groups.yahoo.com/group/linux_forensics/message/3153</guid>
      <description>linkblast: https://blogs.sans.org/computer-forensics/2009/07/10/office-2007-metadata/ http://blog.kiddaland.net/dw/cat_open_xml.pl </description>
    </item>
    <item>
      <title>Re: MS Office meta data</title>
      <pubDate>Thu, 08 Oct 2009 21:10:49 GMT</pubDate>
      <dc:creator>Lehr, John</dc:creator>
      <link>http://tech.groups.yahoo.com/group/linux_forensics/message/3152</link>
      <guid isPermaLink="true">http://tech.groups.yahoo.com/group/linux_forensics/message/3152</guid>
      <description>Take a look here for several ideas: http://viaforensics.com/computer-forensic-howtos/howto-extract-metadata- microsoft-word-linux.html </description>
    </item>
    <item>
      <title>Re: MS Office meta data</title>
      <pubDate>Thu, 08 Oct 2009 21:03:17 GMT</pubDate>
      <dc:creator>sean.mclinden</dc:creator>
      <link>http://tech.groups.yahoo.com/group/linux_forensics/message/3151</link>
      <guid isPermaLink="true">http://tech.groups.yahoo.com/group/linux_forensics/message/3151</guid>
      <description>Payne Consulting&#39;s Metadata Assistant for versions of Office prior to 2007. Make sure that you have Office 2003 installed not Office 2007 and don&#39;t convert</description>
    </item>
    <item>
      <title>MS Office meta data</title>
      <pubDate>Thu, 08 Oct 2009 20:36:50 GMT</pubDate>
      <dc:creator>Donald Raikes</dc:creator>
      <link>http://tech.groups.yahoo.com/group/linux_forensics/message/3150</link>
      <guid isPermaLink="true">http://tech.groups.yahoo.com/group/linux_forensics/message/3150</guid>
      <description>Hi all, Please forgive the cross-posting. I am trying to find any information on MS office metadata, and how to extract it. Is there a spec available for</description>
    </item>
    <item>
      <title>SFDumper 2.1</title>
      <pubDate>Tue, 06 Oct 2009 09:32:06 GMT</pubDate>
      <dc:creator>Nanni Bassetti</dc:creator>
      <link>http://tech.groups.yahoo.com/group/linux_forensics/message/3149</link>
      <guid isPermaLink="true">http://tech.groups.yahoo.com/group/linux_forensics/message/3149</guid>
      <description>We brought out the SFDumper 2.1, now finally all the problems on the file names and filtering by extension have been resolved. Try it: </description>
    </item>
    <item>
      <title>Re: Tampered data</title>
      <pubDate>Sun, 04 Oct 2009 16:10:07 GMT</pubDate>
      <dc:creator>nehal dattani</dc:creator>
      <link>http://tech.groups.yahoo.com/group/linux_forensics/message/3148</link>
      <guid isPermaLink="true">http://tech.groups.yahoo.com/group/linux_forensics/message/3148</guid>
      <description>Hi  farmerdude I am looking for a feature in web server that is it possible to IDENTIFY about status of data. I mean that weather it is system/browser</description>
    </item>
    <item>
      <title>Re: cloning partitions</title>
      <pubDate>Sun, 04 Oct 2009 01:28:45 GMT</pubDate>
      <dc:creator>Jacques B.</dc:creator>
      <link>http://tech.groups.yahoo.com/group/linux_forensics/message/3147</link>
      <guid isPermaLink="true">http://tech.groups.yahoo.com/group/linux_forensics/message/3147</guid>
      <description>Although I normally don&#39;t top post, I suspect that is probably more practical in your case.  Not sure if the accessibility software properly skips to the</description>
    </item>
    <item>
      <title>Re: cloning partitions</title>
      <pubDate>Sun, 04 Oct 2009 01:06:34 GMT</pubDate>
      <dc:creator>Donald Raikes</dc:creator>
      <link>http://tech.groups.yahoo.com/group/linux_forensics/message/3146</link>
      <guid isPermaLink="true">http://tech.groups.yahoo.com/group/linux_forensics/message/3146</guid>
      <description>Jacques, Thank you for the honest response and warnings. I realize there are some real issues with trying to hunt this down, however, since I have been</description>
    </item>
    <item>
      <title>Re: Tampered data</title>
      <pubDate>Sat, 03 Oct 2009 23:05:32 GMT</pubDate>
      <dc:creator>farmerdude</dc:creator>
      <link>http://tech.groups.yahoo.com/group/linux_forensics/message/3145</link>
      <guid isPermaLink="true">http://tech.groups.yahoo.com/group/linux_forensics/message/3145</guid>
      <description>Hi Nehal, Are you looking to identify if the Tamper Data plugin was installed on a system, or something else?  Am not clear. Cheers! farmerdude </description>
    </item>

  </channel>
</rss>
<!-- wr2.grp.sp2.yahoo.com uncompressed/chunked Fri Dec 18 06:04:05 PST 2009 -->
