11-04-2012, 10:11 PM
foremost merupakan app forensic dengan cara merecover file base headers,footers,dan data internal.foremost bisa mengambil data gambar seperti yang digenerate oleh dd, Safeback, encase, dll, atau langsung pada drive. Artikel pendek ini akan membahas bagaimana Anda dapat menggunakan dan menggambil file yang telah dihapus.
--foremost dibuat oleh lab departement komputer forensic USA tahun 1999.
BACKTRACK==>FORENSIC==>FORENSIC CARVING TOOLS==>FOREMOST
Tata cara penggunaan dan command untuk menjalankan tools foremost
lebih lengkapnya command = man foremost
Jenis-jenis file yang mendukung foremost:
jpg - Support for the JFIF and Exif formats including implementations used in modern digital cameras.
gif
png
bmp - Support for windows bmp format.
avi
exe - Support for Windows PE binaries, will extract DLL and EXE files along with their compile times.
mpg - Support for most MPEG files (must begin with 0x000001BA)
wav
riff - This will extract AVI and RIFF since they use the same file format (RIFF). note faster than running each separately.
wmv - Note may also extract -wma files as they have similar format.
mov
pdf
ole - This will grab any file using the OLE file structure. This includes PowerPoint, Word, Excel, Access, and StarWriter
doc - Note it is more efficient to run OLE as you get more bang for your buck. If you wish to ignore all other ole files then use this.
zip - Note is will extract .jar files as well because they use a similar format. Open Office docs are just zipâd XML files so they are extracted
as well. These include SXW, SXC, SXI, and SX? for undetermined OpenOffice files.
rar
htm
cpp - C source code detection, note this is primitive and may generate documents other than C code.
sebelumnya kita mendetek lokasi drive kita
fdisk -l
lokasi pendrive saya di /dev/sdc1
Ok kita akan mengambil file.exe yang ada di pendrive saya tadi
Hasilnya...bisa kita lihat di directory ./ROOT
[HIDE]
[/HIDE]
Untuk pencarian file yang lain silahkan dicoba....untuk mengambil file yang telah terhapus semakin banyak dan besar file yang akan di recover semakin lama waktu yang dibutuhkan. Happy Forensic.
Untuk Tutorial Forensic Yang saya posting di IBT silahkan dibaca bagi yg belum:
FATBACK
TRUECRYPT
Recoverjpg
Tunggu Kelanjutannya ya!!!!!!!!!!!!!!
--foremost dibuat oleh lab departement komputer forensic USA tahun 1999.
BACKTRACK==>FORENSIC==>FORENSIC CARVING TOOLS==>FOREMOST
Tata cara penggunaan dan command untuk menjalankan tools foremost
lebih lengkapnya command = man foremost
Jenis-jenis file yang mendukung foremost:
jpg - Support for the JFIF and Exif formats including implementations used in modern digital cameras.
gif
png
bmp - Support for windows bmp format.
avi
exe - Support for Windows PE binaries, will extract DLL and EXE files along with their compile times.
mpg - Support for most MPEG files (must begin with 0x000001BA)
wav
riff - This will extract AVI and RIFF since they use the same file format (RIFF). note faster than running each separately.
wmv - Note may also extract -wma files as they have similar format.
mov
ole - This will grab any file using the OLE file structure. This includes PowerPoint, Word, Excel, Access, and StarWriter
doc - Note it is more efficient to run OLE as you get more bang for your buck. If you wish to ignore all other ole files then use this.
zip - Note is will extract .jar files as well because they use a similar format. Open Office docs are just zipâd XML files so they are extracted
as well. These include SXW, SXC, SXI, and SX? for undetermined OpenOffice files.
rar
htm
cpp - C source code detection, note this is primitive and may generate documents other than C code.
sebelumnya kita mendetek lokasi drive kita
fdisk -l
lokasi pendrive saya di /dev/sdc1
Ok kita akan mengambil file.exe yang ada di pendrive saya tadi
Hasilnya...bisa kita lihat di directory ./ROOT
[HIDE]
[/HIDE]
Untuk pencarian file yang lain silahkan dicoba....untuk mengambil file yang telah terhapus semakin banyak dan besar file yang akan di recover semakin lama waktu yang dibutuhkan. Happy Forensic.
Untuk Tutorial Forensic Yang saya posting di IBT silahkan dibaca bagi yg belum:
FATBACK
TRUECRYPT
Recoverjpg
Tunggu Kelanjutannya ya!!!!!!!!!!!!!!
The Wolf