Create an account Home  ·  Topics  ·  Downloads  ·  Your Account  ·  Submit News  ·  Top 10  
· Home
· Content
· Forensic Downloads
· Forensics Feedback
· Forums
· Members List
· Statistics
· Surveys
· Top 10
· Topics
· Training Reviews
· Web Links
· Your Account

Our Membership

Latest: ylq
New Today: 1
New Yesterday: 3
Overall: 29710

Computer Forensics
This is a free and open peer to peer medium for digital and computer forensics professionals and students. Please help us maintain it by contributing and perhaps linking to us from your own website.

Recent Posts

 With the drizzle, a round of crescent
 the sunset kisses the Western Hills
 eSoftTools Excel Password Unlocker
 Ceiling suppliers
 Red Raspberry Extract Wholesale

Computer Forensics World Forums

Pages Served
We received
page views since August 2004

Security Sources

OnGuard Online
ISO 17799 ISO 27001
ISO 27000 Toolkit
ISO 27001 & 27000
Security Policies

Computer Forensics World: Forums

Computer Forensics World :: Search
 Forum FAQForum FAQ   SearchSearch   UsergroupsUsergroups   ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 

Search found 241 matches
Computer Forensics World Forum Index
Author Message
  Topic: Computer Forensics Investigation Process

Replies: 4
Views: 1377

PostForum: Miscellaneous   Posted: Fri May 18, 2018 1:28 am   Subject: Re: Computer Forensics Investigation Process
I was assigned to do computer forensics investigation . Where should i start ?

Learn IT fundamentals

Learn platform specifics

Learn forensics (local law and other basics etc.)

At that poin ...
  Topic: is it possible to verify if a HDD was wiped with DBAN

Replies: 1
Views: 2071

PostForum: Technical Issues   Posted: Fri Apr 06, 2018 12:49 am   Subject: Re: is it possible to verify if a HDD was wiped with DBAN
I would like to know if it is possible to detect if a HDD was wiped using a tool like DBAN ??

Yes. If the tool in question leaves traces of its operation that is unique, it is possible.
  Topic: Disk Image

Replies: 1
Views: 2015

PostForum: Forensic Software and Tools   Posted: Tue Dec 05, 2017 2:22 am   Subject: Re: Disk Image
What is a disk image in computer forensics? What sort of strategy would we be able to use for making a picture without utilizing the product?

And, pray, why do you care? Who are you? What purpose i ...
  Topic: Hash calculation between image and original file

Replies: 1
Views: 3035

PostForum: Technical Issues   Posted: Sat Sep 30, 2017 4:24 pm   Subject: Re: Hash calculation between image and original file
1) I want to know how they calculate hash among original file location and image file. Source location have several folders.

You may need to try to rephrase that question: I'm not sure I understand ...
  Topic: Final Year Project

Replies: 1
Views: 3869

PostForum: Miscellaneous   Posted: Sat Sep 02, 2017 5:57 am   Subject: Re: Final Year Project
I currently doing Bachelor in Computer Forensic and about to do Final Year Project .
I would like to know what type of idea I should do for my project?

Talk to your professor or head teacher or co ...
  Topic: Viewing real MAC times of a timestomped file

Replies: 1
Views: 3938

PostForum: Forensic Software and Tools   Posted: Mon Jun 26, 2017 5:11 am   Subject: Re: Viewing real MAC times of a timestomped file
Is there any way for me to view the correct MAC times for a files that have their MAC times modified with Timestomp?

No. The timestamps have been overwritten.

There may be special situations (s ...
  Topic: software that can view files in Volume Slack

Replies: 2
Views: 4756

PostForum: Forensic Software and Tools   Posted: Sun Jun 25, 2017 5:49 pm   Subject: Re: software that can view files in Volume Slack
Can someone recommend a software that can extract/view files directly from the Volume Slack of a dd file?

You may want to clarify your use of the term 'volume slack'.

To me, it means the space b ...
  Topic: Questionnaire on Tool Testing in DF

Replies: 0
Views: 4472

PostForum: General Computer Forensic Issues   Posted: Sat May 27, 2017 6:40 pm   Subject: Questionnaire on Tool Testing in DF
This is probably of wider interest ...

Dr. Graeme Horsman (Durham University, I believe) has posted a questionnaire on tool testing in DF, with a cover message over in ForensicsFocus.

The quest ...
  Topic: Covert Aff to DD

Replies: 2
Views: 3658

PostForum: Forensic Software and Tools   Posted: Wed May 24, 2017 1:21 am   Subject: Re: Covert Aff to DD
I'm new to the Forensic world and self learning using open-source tools. The question that l would like to ask is, I have an .aff image and I want to convert it dd and RAW file. How do I go about it u ...
  Topic: The unallocated space on a windows 7 and Ubuntu dual boot

Replies: 1
Views: 4531

PostForum: Technical Issues   Posted: Sat Mar 18, 2017 5:09 am   Subject: Re: The unallocated space on a windows 7 and Ubuntu dual boo
When someone deletes something from windows OS, can that deleated file be carved out from the Linux side of the dual boot?

The Linux end would very probably see the same volume, and if good carving ...
  Topic: File path in the URL field in Internet Evidence Finder

Replies: 2
Views: 5416

PostForum: Technical Issues   Posted: Wed Mar 01, 2017 3:34 am   Subject: Re: File path in the URL field in Internet Evidence Finder
I have an IEF report here that a colleague of mine needed help deciphering. In the "URL" field in the Internet explorer main history, are file names and the path in which to find the files. The files ...
  Topic: Forensic computing & security degree vs Software enginee

Replies: 6
Views: 9660

PostForum: Digital Forensics: Getting Started   Posted: Fri Jan 06, 2017 6:02 pm   Subject: Forensic computing & security degree vs Software enginee
I would ask you, when you troll the job boards ...

Unfortunate choice of words, I fear, as 'trolling' often is strongly associated with deception.

'trawl' is probably what was intended.
  Topic: How to determine if File Creation Date is correct

Replies: 9
Views: 21535

PostForum: Technical Issues   Posted: Thu Dec 01, 2016 6:12 am   Subject: How to determine if File Creation Date is correct
Also another kinda silly way of checking, but if you have files that are "older" than the ones put on the machine when windows was installed, could that indicate a bit of mucking with the time system? ...
  Topic: Why examine the swap file last?

Replies: 2
Views: 6166

PostForum: Training and Education   Posted: Thu Dec 01, 2016 6:05 am   Subject: Re: Why examine the swap file last?
I read that when attempting to recover a lost file you should examine the swap file last if other attempts/methods have failed...why is that? I know that the swap file acts as a virtual memory extensi ...
  Topic: Computer evidence IP

Replies: 3
Views: 6109

PostForum: Technical Issues   Posted: Sat Nov 19, 2016 5:53 pm   Subject: Re: Computer evidence IP
1. Is there any malware which change this IP?
2. In case that someone has changed this registry key and taking account that we had to change because the user needed to access applications and email, ...
Page 1 of 17 Goto page 1, 2, 3 ... 15, 16, 17  Next
All times are GMT + 10 Hours
Jump to:  

Powered by phpBB 2.0.10 © 2001 phpBB Group
phpBB port v2.1 based on Tom Nitzschner's phpbb2.0.6 upgraded to phpBB 2.0.4 standalone was developed and tested by:
ArtificialIntel, ChatServ, mikem,
sixonetonoffun and Paul Laudanski (aka Zhen-Xjell).

Version 2.1 by Nuke Cops 2003

Forums ©


TMs property of their respective owner. Comments property of posters. 2007 Computer Forensics Science World.
Digital forensic computing news syndication: Computer Forensics Training News or UM Text
Software is copyrighted (c)2003, and is free under licence agreement. All Rights Are Reserved.