CS 381.3 Forensic Computing, Spring 2007
	
	Here you may find things relevant to this class. 

	Class Information   Books, Policies and more
	Links               Links to tools and other interesting things.
	Books               Suggested reading [not mandatory].
    	Class Schedule 	    Tentative class schedule [with readings listed].
	Code Examples

	Announcements
        5/19: Due dates
        All homeworks and final projects are due by Sunday May 20th at
        2:00pm.  What I am expecting:
        1) Blog
        2) find command for SUID and GUID files
        3) Paper
        4) Cases 1-3.  For the cases you must list all files that were
           found including md5sums and the methodology that you used 
           to extract/find them.  This is in addition to just 
           answering the questions
        
        5/13: Part III network traces
        This shows extraction of files from TCP streams.  
        You should have received an email decribing this as well.

        5/8: Part IV
        Patched zip file link was emailed to you.

        5/1: Part III
        Here is the image

        4/26: Questions
        The questions for your paper are now up.

        4/24: Final Project Part 1
        Here is the image
    
        2/22: pcat and test1.c test2.c
        My directory is /home/faculty/jlevy  Those files are there.
        Copy them. HW 3 can be found Here.
        Cygwin instructions can be found Here.

        2/13: EtherApe
        The graphical network monitor I was discussing is called: EtherApe.
        Screenshots are available on the referenced website.

        2/8: VoIP
        The VoIP program I was discussing is called jajah.  
    
    	2/5: Blogs
	Information for the blogs can be found HERE.

	If you do not have a Linux/Unix Machine at home, try to install Cygwin 
	on your windows computer. Tools that we will use for sure are:

	Sleuthkit
	Autopsy Browser
	Foremost
If you are installing on a Cygwin environment, make sure to get the source code. Also, make sure to install Sleuthkit first. When you have placed in a place you can reach from within the Cygwin environment, unzip each tar ball:

$ tar -xzvf [name_of_file]

Then go into the resulting folder and run the ``configure'' file. Then type `make' without quotes:

$ make

If you are successful, you will not see any error messages and you will something like ``check ok.'' Here are some images:

  1. Autopsy [installation]
  2. Autopsy [running]


QC > QC CS Dept > J. Levy Homepage > CS 381.3

Last Modified:

Jamie L. Levy
Computer Science Department
Queens College, CUNY