Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 57 guests online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum arrow Ethical Hacking Discussions and Related Certificationsarrow Forensicsarrow Forensic....."Ram dumping"
EH-Net
May 24, 2012, 10:09:25 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Forensic....."Ram dumping"  (Read 2921 times)
0 Members and 1 Guest are viewing this topic.
Shailendra
Newbie
*
Offline Offline

Posts: 3


View Profile
« on: February 09, 2009, 09:29:49 AM »

The process of capturing the memory is known as dumping. The tools and methods of dumping the memory on a running computer differ with the Operating System.

Eg.

Windows

To dump the memory here we are using dd.exe tool which is available

The command for dumping is:-

C:\users\shailendra>dd.exe if=\\.\PhysicalDrive0 of=d:\images\PhysicalDrive0.img conv=noerror

The command conv=noerror will make the dumping of memory forcefully.

To write the dump image on to hard disk you need to add --localwrt.

This tool is not useful for the windows os which are after 2003 sp1 or Vesta.
Logged

//*pride comes before the fall *//
jason
Hero Member
*****
Offline Offline

Posts: 945



View Profile
« Reply #1 on: February 09, 2009, 09:43:24 AM »

And of course don't forget the cold boot attack

http://citp.princeton.edu/memory/
Logged
vijay2
Full Member
***
Offline Offline

Posts: 220


View Profile
« Reply #2 on: February 10, 2009, 11:48:22 AM »

There are few tools available just for dumping memory.

mdd.exe from Mandiant is for windows
memdump for linux

Mandiant also released a new tool "Memoryze recently. More info can be found at

http://holisticinfosec.org/toolsmith/docs/february2009.pdf

Hope this help

VJ
Logged

GPEN GCFA GCIH CISSP CISA GSEC OSCP C|EH Security+
jason
Hero Member
*****
Offline Offline

Posts: 945



View Profile
« Reply #3 on: February 10, 2009, 12:02:48 PM »

Here's a wiki with a few other links as well:

http://forensics.wikia.com/wiki/RAM_Analysis
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.301 seconds with 23 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge: Build Security Skills to Protect & Defend

els_130x200fixed2.gif
eLearnSecurity Student Course Now Live!
5% Off with Code
ELS-EH-5

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: EHN_Connect Including SANS Security West 2012 & SANSFIRE 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.