Linux Today: Linux News On Internet Time.

More on LinuxToday

Hack and / - Forensics with Ext4

Feb 29, 2012, 21:00 (0 Talkback[s])

"The first problem showed up when I tried to navigate through the filesystem with Autopsy?all of the directories below the root directory appeared to be empty. I knew that couldn't be right, but I wasn't sure what the problem was.

At first, I thought I might just have a corrupted copy of the image, but since the md5sum seemed to take almost as long as copying the image, I started the image copy again from my gold master just to be sure. When that still didn't work, I tried to use Sleuthkit from the command line and even tried tools from The Coroner's Toolkit, yet I got the same result.

Complete Story