Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 79 guests and 1 member online
 
Free Business and Tech Magazines and eBooks

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Forensicsarrow Creating a live cd
EH-Net
May 18, 2013, 01:07:42 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Creating a live cd  (Read 5516 times)
0 Members and 1 Guest are viewing this topic.
jbscarva
Newbie
*
Offline Offline

Posts: 1


View Profile
« on: October 26, 2011, 05:34:51 AM »

I work in computer forensics and I am newbie in Linux, (despite search and study a lot).
However in my Office, we want to develop a "Live CD" - Ubuntu based - for forensic purposes.
One of the main objectives of the CD is to be "forensically sound", eg, none of the devices on the target system should be mounted RW, RO instead.


My question is:
-Can we start from "Ububtu Live CD", install on it some forensic apps, change the boot system and burn all with changes to a new CD?
If so, what we must change in order to ensure that the CD will be "forensically sound"?
Will be that there are batch scripts for this purpose?
 -
Any help is welcome


Thanks in advance and best regards,
Logged
n3r
Jr. Member
**
Offline Offline

Posts: 95



View Profile
« Reply #1 on: October 26, 2011, 07:58:45 AM »

I've never tried but you can try http://www.linux-live.org/
Just install the apps and make an iso with linux live
Logged
chrisj
Hero Member
*****
Offline Offline

Posts: 1163


View Profile WWW
« Reply #2 on: October 26, 2011, 12:37:09 PM »

It's called remastering, I know the Knoppix Hacks book had a section on how to remaster Knoppix for your needs. It was Debain based at the time like Ubuntu, so the theory should carry you.

There are several other options to do that too...

Examples of Remastered versions of Ububuntu:

Backtrack
Xubuntu
Kubuntu
EDUbuntu

I'm sure there are others.
Logged

OSWP, Sec+
tturner
Sr. Member
****
Offline Offline

Posts: 432


View Profile WWW
« Reply #3 on: October 26, 2011, 02:13:16 PM »

You will need to mount the filesystem as read only. Any write operations will compromise your evidence.

Maybe start with options that are already forensically sound and customize from there and then remaster. http://www.forensicswiki.org/wiki/Tools

Logged

Certifications:
CISSP, CISA, GPEN, GWAPT, GAWN, GCIA, GCIH, GSEC, OPSE, CSWAE, CSTP, VCP

WIP: OSWP, GSSP-JAVA, GXPN

Udacity on hold, again. I suck.

http://sentinel24.com/blog  @tonylturner http://bsidesorlando.org
idr0p
Newbie
*
Offline Offline

Posts: 49


View Profile
« Reply #4 on: October 27, 2011, 04:34:37 PM »

Do you need to make one specifically or can you just use one already out there, there are many.

SIFT Kit
Helix
Sleuth kit
Backtrack
etc...
Logged

GCIA GCIH GPEN GWAPT
Up Next: CISA CISSP
p0et
Full Member
***
Offline Offline

Posts: 197



View Profile
« Reply #5 on: October 30, 2011, 01:59:48 PM »

I've heard good things about Sleuth Kit and Helix3.  That would sure save you a ton of time if you could just use one of those!
Logged

GCIH, Security+, Network+, A+, MCP, DCSE
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.113 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.