http://www.porcupine.org/forensics/tct.html
Features Notable TCT components are the grave-robber tool that captures information, the ils and mactime tools that display access patterns of files dead or alive, the unrm and lazarus tools that recover deleted files, and the findkey tool that recovers cryptographic keys from a running process or from files. Never tried it on slackware - only redhat - but should work just the same. hth dbk The genius of you Americans is that you never make any clear-cut stupid moves, only complicated stupid moves that leave us scratching our heads wondering if we might possibly have missed something. -- Gamel Abdel Nasser David Knapp Network Analyst, CSA Cal Poly State University, SLO [EMAIL PROTECTED] -----Original Message----- From: sousaferreira [mailto:[EMAIL PROTECTED]] Sent: Friday, January 11, 2002 1:16 AM To: security-basics Cc: sousaferreira Subject: Urgent -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 How can i undelete files on an ext2 partition running slack 7.1 ???? A normal user deleted some of his own files and now is trying to comit suicide ;). Thanks for youy prompt awnser. Best Regards Sousa Ferreira PGP KeyID : 0xB7723B21 --- Outgoing mail is certified Virus Free. Checked by AVG anti-virus system (http://www.grisoft.com). Version: 6.0.314 / Virus Database: 175 - Release Date: 1/11/2002
