Ôö¼ÓVMwareÏÂLINUXµÄÐéÄâ»ú´ÅÅ̿ռä
1. ¹Ø±ÕÐéÄâ»ú;Æô¶¯WindowsϵÄÃüÁîÌáʾ·û½çÃæ;
¡¡¡¡2. ÃüÁî½øÈëVMwareµÄ°²×°Ä¿Â¼(È磺D:\VMware),ÊäÈë“vmware-vdiskmanager”ºó°´»Ø³µ¼ü£¬¿ÉÏÔʾ¹ØÓÚ¸ÃÃüÁîµÄ˵Ã÷¡£
¡¡¡¡3. Ö´ÐÐÈçÏÂÃüÁvmware-vdiskmanager -x 20Gb "J:\VMware Space\SUSE Linux 64-bit.vmdk"²ÎÊý-x±íʾҪÀ©Õ¹ÐéÄâ»úÓ²Å̿ռä;½ôËæÆäºóµÄÊý×ÖÖ¸ÒªÀ©Õ¹µÄ´óС(Èç20Gb£¬±íʾ´ÅÅÌ×ÜÁ¿£¬°üº¬ÔÀ´µÄ´ÅÅÌÈÝÁ¿);×îºóÊÇÒª²Ù×÷µÄÐéÄâ»úLinuxµÄ¾ßÌåÎļþ¡£Èô·¾¶ÃûÖÐÓпոñ£¬±ØÐëÒÔË«ÒýºÅÀ¨ÆðÀ´¡£
¡¡¡¡µÈ´ýÔ¼20·ÖÖÓ£¬Ö´ÐÐÍê±Ï£¬Í˳öÃüÁîÌáʾ·û´°¿Ú£¬ÖØÆôVMware£¬ÕâʱÐéÄâ»úÓ²Å̿ռäÒѱä³É20GBÁË¡£Õâ¸ö¹ý³ÌÖУ¬ÒѰ²×°µÄLinuxϵͳ²»»á±»ÆÆ»µ¡£
¡¡¡¡Èç¹ûÔÀ´µÄÐéÄâ»úÓ²ÅÌÒѱ»·Ö³ÉÁ˶à¸ö·ÖÇø£¬ÄÇôÔÚͨ¹ý vmware-vdiskmanager.exeÀ©´óÁËÓ²Å̿ռäºó£¬»¹ÐèÒªÔÚÐéÄâ»úϵͳÖн«Ôö¼ÓµÄ·ÖÇø»®·Ö¡¢¸ñʽ»¯¡£
¡¡¡¡4. Æô¶¯ÐéÄâ»úϵͳ£¬ÓÃrootµÇ¼(ºóÐøËùÓв½Öè¶¼Ó¦ÒÔrootÓû§Éí·ÝµÇ¼²Ù×÷)£¬ÔÚ ÃüÁîÐÐÓÃfdisk -l²é¿´¡£ÓÉÓÚÕâÀïÊÇÖ±½ÓÐÞ¸ÄÁËÔʼ¿Õ¼ä´óС£¬Òò´Ë¿ÉÒÔ¿´µ½/dev/sda¿Õ¼ä¸Ä±äΪ21.4GB¡£Èç¹ûÊÇ´ÓVMware²Ëµ¥ÀïÔö¼ÓÐéÄâÓ²ÅÌ£¬Ôò»á¶à³öÒ»¸ö/dev/sd?£¬ÕâÀïµÄ?´ú±íÓ²Å̱àºÅ£¬µÚÒ»¸öÓ²Å̱àºÅΪa¼´sda£¬µÚ¶þ¸ö¾ÍÊÇsdb£¬µÚÈý¸öÊÇsdc£¬ÒÔ´ËÀàÍÆ£¬Ò»°ãÀ´Ëµ£¬Èç¹ûÒÔǰûÓÐÔö¼Ó¹ýÓ²ÅÌ£¬ÄÇôÔÀ´µÄÓ²Å̾ÍÊÇsda£¬Í¨¹ýVMware²Ëµ¥Ôö¼ÓµÄÐéÄâÓ²Å̱àºÅ¾ÍÊÇsdb¡£Èç¹ûÌí¼ÓµÄµÚ¶þ¿éÓ²ÅÌÊÇIDEÓ²ÅÌ£¬¾ÍÓ¦¸Ã¿´µ½hdb£¬Èç¹ûÊÇ SCSIÓ²ÅÌ£¬¿´µ½µÄ¾ÍÓ¦¸ÃÊÇsdb¡£
¡¡¡¡hawkzy:~ # fdisk -l
¡¡¡¡Disk /dev/sda: 21.4 GB, 21474836480 bytes 255 heads, 63 sectors/track, 2610 cylinders
¡¡¡¡Units = cylinders of 16065 * 512 = 8225280 bytes
¡¡¡¡Disk identifier: 0x00067588
¡¡¡¡Device Boot Start End Blocks Id System
¡¡¡¡/dev/sda1 1 95 763056 82 Linux swap / Solaris
¡¡¡¡/dev/sda2 * 96 868 6209122+ 83 Linux
¡¡¡¡/dev/sda3 869 1958 8755425 83 Linux
¡¡¡¡5. ʹÓÃfdisk /dev/sda½øÈë²Ëµ¥ÏmÊÇÁгö²Ëµ¥£¬pÊÇÁгö·ÖÇø±í£¬nÊÇÔö¼Ó·ÖÇø£¬wÊDZ£´æ²¢ÍƳö¡£ÓÉÓÚϵͳÒѾÓÐÁË3¸öÖ÷·ÖÇø£¬Òò´Ë½«Õâ´ÎÐÂÔöµÄ¿Õ¼ä»®·ÖΪÀ©Õ¹·ÖÇø£¬ÔÙ½«À©Õ¹·ÖÇøÖØÐ·ÖÇø¡£ÓÉÓÚÕâÀïÀ©Õ¹·ÖÇøÖ»ÓÐ5G£¬Òò´Ë5G»®ÎªÒ»¸öÇø¡£
¡¡¡¡hawkzy:~ # fdisk /dev/sda
¡¡¡¡Command (m for help): p
¡¡¡¡Disk /dev/sda: 21.4 GB, 21474836480 bytes 255 heads, 63 sectors/track, 2610 cylinders
¡¡¡¡Units = cylinders of 16065 * 512 =
Ïà¹ØÎĵµ£º
ÀýÒ»£º·¢ËÍSignaling Packet£º
Signaling CommandÊÇ2¸öBluetoothʵÌåÖ®¼äµÄL2CAP²ãÃüÁî´«Êä¡£ËùÒÔµÃSignaling CommandʹÓÃCID 0x0001.
¶à¸öCommand¿ÉÒÔÔÚÒ»¸öC-frame£¨control frame£©Öз¢ËÍ¡£
Èç¹ûÒªÖ±½Ó·¢ËÍSignaling Command.ÐèÒª½¨Á¢SOCK_RAWÀàÐ͵ÄL2CAPÁ¬½ÓSocket¡£ÕâÑù²ÅÓлú»á×Ô¼ºÌî³äCommand Code£¬Identi ......
Service Discovery Protocol(SDP)ÌṩһÖÖÄÜÁ¦£¬ÈÃÓ¦ÓóÌÐòÓз½·¨·¢ÏÖÄÄÖÖ·þÎñ¿ÉÓÃÒÔ¼°ÕâÖÖ·þÎñµÄÌØÐÔ¡£
·þÎñ·¢ÏÖÐÒé(SDP»òBluetooth SDP)ÔÚÀ¶ÑÀÐÒéÕ»ÖжÔÀ¶ÑÀ»·¾³ÖеÄÓ¦ÓóÌÐòÓÐÌØÊâµÄº¬Ò⣬·¢ÏÖÄĸö·þÎñÊÇ¿ÉÓõĺÍÈ·¶¨ÕâЩ¿ÉÓ÷þÎñµÄÌØÕ÷¡£SDP¶¨ÒåÁËbluetooth client·¢ÏÖ¿ÉÓÃbluetooth server·þÎñºÍËüÃǵÄÌØÕ÷µÄ·½·¨¡£ ......
×÷Õߣº¿µ»ª,»ªÇåÔ¶¼ûǶÈëʽѧԺ½²Ê¦¡£
1. ¹ØÓÚij¸öµµÃûµÄ¡ºÀàÐÍ¡»Õì²â(´æÔÚÓë·ñ)£¬Èç test -e filename
-e ¸Ã¡ºµµÃû¡»ÊÇ·ñ´æÔÚ£¿(³£ÓÃ)
-f ¸Ã¡ºµµÃû¡»ÊÇ·ñΪµµ°¸(file)£¿(³£ÓÃ)
-d ¸Ã¡ºÎļþÃû¡»ÊÇ·ñΪĿ¼(direct ......
http://www.forensicswiki.org/wiki/Helix3
http://www.sleuthkit.org/index.php
»Ö¸´²½Öè:
root@srv01 [/home/recovery]# ./fls -a -r -p /dev/sdb3 > sdb3usrdirlist.txt
root@srv01 [/home/recovery]# grep -i "access_log" /home/recovery/sdb3usrdirlist.txt
r/r 2195490: local/ ......
ʹÓÃselectº¯Êý¿ÉÒÔÒÔ·Ç×èÈûµÄ·½Ê½ºÍ¶à¸ösocketͨÐÅ¡£³ÌÐòÖ»ÊÇÑÝʾselectº¯ÊýµÄʹÓ㬹¦Äܷdz£¼òµ¥£¬¼´Ê¹Ä³¸öÁ¬½Ó¹Ø±ÕÒÔºóÒ²²»»áÐ޸ĵ±Ç°Á¬½ÓÊý£¬Á¬½ÓÊý´ïµ½×î´óÖµºó»áÖÕÖ¹³ÌÐò¡£
1. ³ÌÐòʹÓÃÁËÒ»¸öÊý×éfd_A£¬Í¨ÐÅ¿ªÊ¼ºó°ÑÐèҪͨÐŵĶà¸ösocketÃèÊö·û¶¼·ÅÈë´ËÊý×é¡£
2. Ê×ÏÈÉú³ÉÒ»¸ö½Ðsock_fdµÄsocketÃèÊö·û£¬ÓÃÓÚ¼àÌý¶Ë¿ ......