The most obvious tool for the task is TCT (The Coroner's Toolkit) by Wietse Venema and Dan Farmer.
http://www.porcupine.org/forensics/tct.html if you have specific questions, there is a mailing list for tct users: * [EMAIL PROTECTED]* Good luck! Sousa Ferreira wrote: > >-----BEGIN PGP SIGNED MESSAGE----- >Hash: SHA1 > >How can i undelete files on an ext2 partition running slack 7.1 ???? > >A normal user deleted some of his own files and now is trying to >comit suicide ;). > > >Thanks for youy prompt awnser. > >Best Regards > >Sousa Ferreira > > > >PGP KeyID : 0xB7723B21 > > > >-----BEGIN PGP SIGNATURE----- >Version: PGP 7.0.4 > >iQA/AwUBPD6tPSNcH2C3cjshEQKA7gCffNvFsYaUTtK0Y16mBv3HapsrMdMAn37L >LAkY9tU2aTIwcFonaG38RsON >=yvgP >-----END PGP SIGNATURE----- >
