Groups
Sign in
Groups
aff-discuss
Conversations
About
Send feedback
Help
aff-discuss
Contact owners and managers
1–30 of 78
Mark all as read
Report group
0 selected
Stumpy S
11/7/12
Extending length of url recovered by BE
Hopefully this may be useful information to users. I am working on capturing and interpreting the
unread,
Extending length of url recovered by BE
Hopefully this may be useful information to users. I am working on capturing and interpreting the
11/7/12
Greg Freemyer
2
9/6/12
Re: sleuthkit 4.0.0 release with fiwalk?
Simson, I see per https://domex.nps.edu/deep/Fiwalk.html, fiwalk is now in Sleuthkit 4.0.0. I've
unread,
Re: sleuthkit 4.0.0 release with fiwalk?
Simson, I see per https://domex.nps.edu/deep/Fiwalk.html, fiwalk is now in Sleuthkit 4.0.0. I've
9/6/12
kartika pertiwi
,
SLG
2
6/5/12
How to Implement AFF to EnCase or FTK
FTK supports AFF; EnCase does not. You can use the affmount command and make an AFF drive appear as a
unread,
How to Implement AFF to EnCase or FTK
FTK supports AFF; EnCase does not. You can use the affmount command and make an AFF drive appear as a
6/5/12
D M
,
Simson Garfinkel
2
5/15/12
idifference timestamp changes are the same (problem)
Thanks for the. I suspect that the problem you are dealing with is actually a problem with timezones
unread,
idifference timestamp changes are the same (problem)
Thanks for the. I suspect that the problem you are dealing with is actually a problem with timezones
5/15/12
D M
,
Simson Garfinkel
2
5/15/12
Bulk Extractor with multipart VMDK ??
Not at the present time. On May 9, 2012, at 8:24 PM, DM wrote: Is it possible to run Bulk Extractor
unread,
Bulk Extractor with multipart VMDK ??
Not at the present time. On May 9, 2012, at 8:24 PM, DM wrote: Is it possible to run Bulk Extractor
5/15/12
D M
,
Simson Garfinkel
2
5/2/12
dfxml.py problems with idifference
Dave, When filing a bug report, please indicate: 1. Are you using Python 2 or Python 3? Which version
unread,
dfxml.py problems with idifference
Dave, When filing a bug report, please indicate: 1. Are you using Python 2 or Python 3? Which version
5/2/12
Simson Garfinkel
,
Kam Woods
2
3/31/12
announcing AFFLIBv3.7 --- AFFLIB moves to github
On Mar 31, 2012, at 8:34 PM, Simson Garfinkel <sim...@acm.org> wrote: ANNOUNCING AFFLIB 3.7 I
unread,
announcing AFFLIBv3.7 --- AFFLIB moves to github
On Mar 31, 2012, at 8:34 PM, Simson Garfinkel <sim...@acm.org> wrote: ANNOUNCING AFFLIB 3.7 I
3/31/12
Greg Freemyer
,
Simson Garfinkel
2
3/19/12
small patch for fiwalk
Thanks. We made the change in all of the various xml.cpp's we have running around. However the
unread,
small patch for fiwalk
Thanks. We made the change in all of the various xml.cpp's we have running around. However the
3/19/12
Greg Freemyer
,
Simson Garfinkel
2
3/27/12
How to install the fiwalk plugins?
I'm sorry, I can't provide you support for the RPMs. fiwalk won't ignore the plugins; you
unread,
How to install the fiwalk plugins?
I'm sorry, I can't provide you support for the RPMs. fiwalk won't ignore the plugins; you
3/27/12
e_tective
,
Simson Garfinkel
2
3/27/12
Understanding "fiwalk"
I am sorry for my delay in responding to this. Without seeing your test.xml file, i cannot provide
unread,
Understanding "fiwalk"
I am sorry for my delay in responding to this. Without seeing your test.xml file, i cannot provide
3/27/12
Andy Schroder
2/29/12
Re: Digest for aff-discuss@googlegroups.com - 1 Message in 1 Topic
syntax: bulk_extractor.exe -o output file [options] IMAGEFILE On Wed, Feb 29, 2012 at 5:54 AM, <
unread,
Re: Digest for aff-discuss@googlegroups.com - 1 Message in 1 Topic
syntax: bulk_extractor.exe -o output file [options] IMAGEFILE On Wed, Feb 29, 2012 at 5:54 AM, <
2/29/12
Dewhirst, Rob
2/28/12
bulk_extractor.exe -o outputdir
What sort of boneheaded thing am I missing here? the windows bulk_extractor doesn't like anything
unread,
bulk_extractor.exe -o outputdir
What sort of boneheaded thing am I missing here? the windows bulk_extractor doesn't like anything
2/28/12
Dewhirst, Rob
,
Simson Garfinkel
4
2/27/12
bulk_extractor seg fault
and of course way too late I discovered this page: http://afflib.org/software/bulk_extractor/
unread,
bulk_extractor seg fault
and of course way too late I discovered this page: http://afflib.org/software/bulk_extractor/
2/27/12
Brad
, …
Simson Garfinkel
9
2/23/12
prove they were a novice or an expert???
Yes. Need to do a better job publicizing it. bulk_extra...@googlegroups.com http://groups.
unread,
prove they were a novice or an expert???
Yes. Need to do a better job publicizing it. bulk_extra...@googlegroups.com http://groups.
2/23/12
Simson Garfinkel
, …
RB
4
2/21/12
New open source forensics mailing list.
On Tue, Feb 21, 2012 at 05:23, Simson Garfinkel <sim...@acm.org> wrote: > I will set up a
unread,
New open source forensics mailing list.
On Tue, Feb 21, 2012 at 05:23, Simson Garfinkel <sim...@acm.org> wrote: > I will set up a
2/21/12
Rob Lee
,
Simson Garfinkel
2
2/20/12
Bulk_Extractor
bulk_extractor just extracts all of the text and recognizes patterns. It doesn't understand the
unread,
Bulk_Extractor
bulk_extractor just extracts all of the text and recognizes patterns. It doesn't understand the
2/20/12
Brad
2/19/12
If you 'HAVE to' knuckle bust it!
I created these little scripts for searching huge data sets and not exhausting memory. bulk_extractor
unread,
If you 'HAVE to' knuckle bust it!
I created these little scripts for searching huge data sets and not exhausting memory. bulk_extractor
2/19/12
Abhishek Sharma
,
Simson Garfinkel
2
1/6/12
Tcpflow development - Merging Flows
Thanks for the email. The program creates two session files because there are two different TCP flows
unread,
Tcpflow development - Merging Flows
Thanks for the email. The program creates two session files because there are two different TCP flows
1/6/12
Dewhirst, Rob
12/15/11
Re: bulk_extractor
Fixed in 1.1.3. Thanks! On Wed, Dec 14, 2011 at 10:48 PM, Simson Garfinkel <sim...@acm.org>
unread,
Re: bulk_extractor
Fixed in 1.1.3. Thanks! On Wed, Dec 14, 2011 at 10:48 PM, Simson Garfinkel <sim...@acm.org>
12/15/11
Greg Freemyer
2
11/26/11
afflib patch to handle the new lib: tinfo
Simson, The opensuse ncurses package got some extra magic and no longer needs the below patch. I don
unread,
afflib patch to handle the new lib: tinfo
Simson, The opensuse ncurses package got some extra magic and no longer needs the below patch. I don
11/26/11
Dewhirst, Rob
, …
Simson Garfinkel
3
12/14/11
bulk_extractor 1.1.2 make error
Okay. This seems to be an old version of exiv2 installed. Apparently it works with new versions of
unread,
bulk_extractor 1.1.2 make error
Okay. This seems to be an old version of exiv2 installed. Apparently it works with new versions of
12/14/11
Greg Freemyer
12/12/11
a small patch for aimage
Simson, I just packaged up aimage-3.2.5 for openSUSE. I'll send it to their security repo as soon
unread,
a small patch for aimage
Simson, I just packaged up aimage-3.2.5 for openSUSE. I'll send it to their security repo as soon
12/12/11
Dewhirst, Rob
, …
Simson Garfinkel
9
10/27/11
Distributed bulk_extractor?
Thanks for the clarification. It would certainly be useful to have a peer-to-peer option in
unread,
Distributed bulk_extractor?
Thanks for the clarification. It would certainly be useful to have a peer-to-peer option in
10/27/11
KDawg44
,
Simson Garfinkel
3
8/31/11
AFFLIB Compile error
On Wed, Aug 31, 2011 at 10:46 PM, Simson Garfinkel <sim...@acm.org> wrote: Cygwin is not
unread,
AFFLIB Compile error
On Wed, Aug 31, 2011 at 10:46 PM, Simson Garfinkel <sim...@acm.org> wrote: Cygwin is not
8/31/11
Jon Stewart
,
Simson Garfinkel
2
8/31/11
json ripper
The JSON carver is finished and in the development tree. The next release will have it. I can get you
unread,
json ripper
The JSON carver is finished and in the development tree. The next release will have it. I can get you
8/31/11
Yaniv
, …
SLG
7
6/30/11
Bulk Extractor and E0 Files
Please review the usage: bulk_extractor -o outputdir image.E01 The image goes last. On Jun 30, 2:28
unread,
Bulk Extractor and E0 Files
Please review the usage: bulk_extractor -o outputdir image.E01 The image goes last. On Jun 30, 2:28
6/30/11
Charlie
,
Simson Garfinkel
2
5/25/11
Bulk_Extractor output
Hi, Charlie. You may wish to move this to the newly-created bulk_extractor user's mailing list,
unread,
Bulk_Extractor output
Hi, Charlie. You may wish to move this to the newly-created bulk_extractor user's mailing list,
5/25/11
Stephanie S
,
Simson Garfinkel
2
5/20/11
fiwalk_using_sax and split images
give fiwalk_using_sax the XML file generated by fiwalk, or a file handle to the first image.
unread,
fiwalk_using_sax and split images
give fiwalk_using_sax the XML file generated by fiwalk, or a file handle to the first image.
5/20/11
Brian Durack
,
Simson Garfinkel
2
5/4/11
pyaff error
pyaff is a standard python module, so you need to do either: import pyaff fd = pyaff.pyaff("file
unread,
pyaff error
pyaff is a standard python module, so you need to do either: import pyaff fd = pyaff.pyaff("file
5/4/11
Benjamin Brink
, …
Simson Garfinkel
8
3/24/11
'bus err' response, aimage
On Mar 24, 2011, at 3:41 PM, tobermory wrote: > Ah, my bad on both counts. Thanks for locating
unread,
'bus err' response, aimage
On Mar 24, 2011, at 3:41 PM, tobermory wrote: > Ah, my bad on both counts. Thanks for locating
3/24/11