The most obvious tool for the task is TCT (The Coroner's Toolkit) by 
Wietse Venema and Dan Farmer.

http://www.porcupine.org/forensics/tct.html

if you have specific questions, there is a mailing list for tct users:
*
[EMAIL PROTECTED]*

Good luck!

Sousa Ferreira wrote:

> 
>-----BEGIN PGP SIGNED MESSAGE-----
>Hash: SHA1
>
>How can i undelete files on an ext2 partition running slack 7.1 ????
> 
>A normal user deleted some of his own files and now is trying to
>comit suicide ;).
> 
> 
>Thanks for youy prompt awnser.
> 
>Best Regards
> 
>Sousa Ferreira
> 
>
>
>PGP KeyID : 0xB7723B21
>
> 
>
>-----BEGIN PGP SIGNATURE-----
>Version: PGP 7.0.4
>
>iQA/AwUBPD6tPSNcH2C3cjshEQKA7gCffNvFsYaUTtK0Y16mBv3HapsrMdMAn37L
>LAkY9tU2aTIwcFonaG38RsON
>=yvgP
>-----END PGP SIGNATURE-----
>



Reply via email to