<?xml version="1.0"?>
<?xml-stylesheet type="text/css" href="http://www.forensicswiki.org/w/skins/common/feed.css?303"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>http://www.forensicswiki.org/w/api.php?action=feedcontributions&amp;user=Pmow&amp;feedformat=atom</id>
		<title>Forensics Wiki - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="http://www.forensicswiki.org/w/api.php?action=feedcontributions&amp;user=Pmow&amp;feedformat=atom"/>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Special:Contributions/Pmow"/>
		<updated>2013-06-20T09:03:55Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.21.1</generator>

	<entry>
		<id>http://www.forensicswiki.org/wiki/VMWare_from_hard_drive_images</id>
		<title>VMWare from hard drive images</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/VMWare_from_hard_drive_images"/>
				<updated>2012-03-23T17:56:15Z</updated>
		
		<summary type="html">&lt;p&gt;Pmow: added result picture&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Category:Howtos]]&lt;br /&gt;
&lt;br /&gt;
== Creating virtual machines from forensic images ==&lt;br /&gt;
&lt;br /&gt;
After having no success with raw2vmdk, the Live View method has worked.&lt;br /&gt;
&lt;br /&gt;
[http://liveview.sourceforge.net/index.html Live View] requires:&lt;br /&gt;
&lt;br /&gt;
-Java JRE&lt;br /&gt;
&lt;br /&gt;
-VMWare Workstation 5.5+ or Server&lt;br /&gt;
&lt;br /&gt;
-VMWare VDDK ([http://www.vmware.com/support/developer/vddk download])&lt;br /&gt;
&lt;br /&gt;
== Install ==&lt;br /&gt;
Install prerequisites followed by Live View (the installer will check for pre-reqs).&lt;br /&gt;
&lt;br /&gt;
''Tested: Win7-64 with VMWare Workstation 7.12, Live View 0.7b, and VMWare VDDK 5.0''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:LiveView.png]]&lt;br /&gt;
&lt;br /&gt;
== VMX Creation ==&lt;br /&gt;
&lt;br /&gt;
1. Run Live View as Administrator. ''(Messages pane will result in errors otherwise)''&lt;br /&gt;
&lt;br /&gt;
2. Set memory and OS as closely as possible to target machine specs. ''(To maximize probability of success)''&lt;br /&gt;
&lt;br /&gt;
3. Click &amp;quot;Start&amp;quot;.  ''(The screenshot error relates to maximums exceeded based on client machine.)''&lt;br /&gt;
&lt;br /&gt;
[[File:VMWareWorkstation.png]]&lt;/div&gt;</summary>
		<author><name>Pmow</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/File:VMWareWorkstation.png</id>
		<title>File:VMWareWorkstation.png</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/File:VMWareWorkstation.png"/>
				<updated>2012-03-23T17:55:24Z</updated>
		
		<summary type="html">&lt;p&gt;Pmow: Screenshot of VMWare workstation running from DD image&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Screenshot of VMWare workstation running from DD image&lt;/div&gt;</summary>
		<author><name>Pmow</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/VMWare_from_hard_drive_images</id>
		<title>VMWare from hard drive images</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/VMWare_from_hard_drive_images"/>
				<updated>2012-03-23T17:41:52Z</updated>
		
		<summary type="html">&lt;p&gt;Pmow: Added complete text steps.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Category:Howtos]]&lt;br /&gt;
&lt;br /&gt;
== Creating virtual machines from forensic images ==&lt;br /&gt;
&lt;br /&gt;
After having no success with raw2vmdk, the Live View method has worked.&lt;br /&gt;
&lt;br /&gt;
[http://liveview.sourceforge.net/index.html Live View] requires:&lt;br /&gt;
&lt;br /&gt;
-Java JRE&lt;br /&gt;
&lt;br /&gt;
-VMWare Workstation 5.5+ or Server&lt;br /&gt;
&lt;br /&gt;
-VMWare VDDK ([http://www.vmware.com/support/developer/vddk download])&lt;br /&gt;
&lt;br /&gt;
== Install ==&lt;br /&gt;
Install prerequisites followed by Live View (the installer will check for pre-reqs).&lt;br /&gt;
&lt;br /&gt;
''Tested: Win7-64 with VMWare Workstation 7.12, Live View 0.7b, and VMWare VDDK 5.0''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:LiveView.png]]&lt;br /&gt;
&lt;br /&gt;
== VMX Creation ==&lt;br /&gt;
&lt;br /&gt;
1. Run Live View as Administrator. ''(Messages pane will result in errors otherwise)''&lt;br /&gt;
&lt;br /&gt;
2. Set memory and OS as closely as possible to target machine specs. ''(To maximize probability of success)''&lt;br /&gt;
&lt;br /&gt;
3. Click &amp;quot;Start&amp;quot;.  ''(The screenshot error relates to maximums exceeded based on client machine.)''&lt;/div&gt;</summary>
		<author><name>Pmow</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/File:LiveView.png</id>
		<title>File:LiveView.png</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/File:LiveView.png"/>
				<updated>2012-03-23T17:32:16Z</updated>
		
		<summary type="html">&lt;p&gt;Pmow: Live View 0.7b screenshot&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Live View 0.7b screenshot&lt;/div&gt;</summary>
		<author><name>Pmow</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/VMWare_from_hard_drive_images</id>
		<title>VMWare from hard drive images</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/VMWare_from_hard_drive_images"/>
				<updated>2012-03-23T17:29:58Z</updated>
		
		<summary type="html">&lt;p&gt;Pmow: Created page with &amp;quot;Category:Howtos  == Creating virtual machines from forensic images ==  After having no success with raw2vmdk, the Live View method has worked.  [http://liveview.sourceforg...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Category:Howtos]]&lt;br /&gt;
&lt;br /&gt;
== Creating virtual machines from forensic images ==&lt;br /&gt;
&lt;br /&gt;
After having no success with raw2vmdk, the Live View method has worked.&lt;br /&gt;
&lt;br /&gt;
[http://liveview.sourceforge.net/index.html Live View] requires:&lt;br /&gt;
&lt;br /&gt;
-Java JRE&lt;br /&gt;
&lt;br /&gt;
-VMWare Workstation 5.5+ or Server&lt;br /&gt;
&lt;br /&gt;
-VMWare VDDK ([http://www.vmware.com/support/developer/vddk download])&lt;/div&gt;</summary>
		<author><name>Pmow</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/User:Pmow</id>
		<title>User:Pmow</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/User:Pmow"/>
				<updated>2012-03-23T17:12:39Z</updated>
		
		<summary type="html">&lt;p&gt;Pmow: updated new company name&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Meatspace Name==&lt;br /&gt;
Gabriel Campos&lt;br /&gt;
&lt;br /&gt;
==Location==&lt;br /&gt;
[http://www.marcumllp.com Marcum LLP]&lt;br /&gt;
&lt;br /&gt;
[http://www.google.com/maps?f=q&amp;amp;hl=en&amp;amp;geocode=&amp;amp;q=Miami,+FL&amp;amp;ie=UTF8&amp;amp;layer=x&amp;amp;ll=25.760938,-80.237274&amp;amp;spn=0.44834,0.683899&amp;amp;z=11 Miami, Florida]&lt;br /&gt;
&lt;br /&gt;
==Contact==&lt;br /&gt;
[mailto:gcampos@rachlin.com gcampos@rachlin.com]&lt;/div&gt;</summary>
		<author><name>Pmow</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/VirtualMachineForensics</id>
		<title>VirtualMachineForensics</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/VirtualMachineForensics"/>
				<updated>2012-03-23T17:10:13Z</updated>
		
		<summary type="html">&lt;p&gt;Pmow: moved VirtualMachineForensics to Forensics of Virtualization Products: The title can easily refer to using virtualization in your forensics practice.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;#REDIRECT [[Forensics of Virtualization Products]]&lt;/div&gt;</summary>
		<author><name>Pmow</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Forensics_of_Virtualization_Products</id>
		<title>Forensics of Virtualization Products</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Forensics_of_Virtualization_Products"/>
				<updated>2012-03-23T17:10:12Z</updated>
		
		<summary type="html">&lt;p&gt;Pmow: moved VirtualMachineForensics to Forensics of Virtualization Products: The title can easily refer to using virtualization in your forensics practice.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Category:Howtos]]&lt;br /&gt;
&lt;br /&gt;
== Dealing with Virtual Machine Images ==&lt;br /&gt;
&lt;br /&gt;
It is becoming increasingly common to find evidence drives with Virtual Machines (VM) on them.  The VMs may contain evidence of their own, but with their unique file structure, care must be taken during examination.  Running the virtual machine could destroy artifacts that are important.&lt;br /&gt;
&lt;br /&gt;
=== Virtual Box ===&lt;br /&gt;
&lt;br /&gt;
There are two methods for creating a way to mount or inspect a Virtual Box VM.  Virtual Box disks typically have the extension &amp;quot;vdi&amp;quot; for Virtual Desktop Infrastructure.  The mount method requires a Linux system and &amp;quot;qemu&amp;quot;.  The other method converts a vdi to a raw image format which can then be inspected with traditional forensics tools.&lt;br /&gt;
&lt;br /&gt;
==== Mount ====&lt;br /&gt;
&lt;br /&gt;
# Install qemu-kvm using your preferred installation tool (apt-get, etc)&lt;br /&gt;
# Load the network block device module  &amp;gt;sudo modprobe nbd&lt;br /&gt;
# Use Qemu to load the VDI file as a loop back device  &amp;gt;sudo qemu-nbd -c /dev/nbd0 infile.vdi&lt;br /&gt;
# Mount  &amp;gt;sudo mount /dev/nbd0p1 /mnt&lt;br /&gt;
# Inspect the file system as needed&lt;br /&gt;
&lt;br /&gt;
To undo:&lt;br /&gt;
# &amp;gt;sudo umount /mnt&lt;br /&gt;
# &amp;gt;qemu-nbd -d /dev/nbd0&lt;br /&gt;
&lt;br /&gt;
[http://bethesignal.org/blog/2011/01/05/how-to-mount-virtualbox-vdi-image/| Source Blog]&lt;br /&gt;
&lt;br /&gt;
==== Convert ====&lt;br /&gt;
&lt;br /&gt;
Conversion requires the Virtual Box tool kit, if you don't already have it.&lt;br /&gt;
&lt;br /&gt;
# Install virtualbox-ose using your preferred installation tool (apt-get, download from VirtualBox.org, etc)&lt;br /&gt;
# Convert to raw format  &amp;gt;VBoxManage internalcommands converttoraw infile.vdi outfile.img&lt;br /&gt;
# Inspect the raw image as per usual, either with TSK, EnCase, or mount&lt;br /&gt;
&lt;br /&gt;
=== VMWare ===&lt;/div&gt;</summary>
		<author><name>Pmow</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/User_talk:Pmow</id>
		<title>User talk:Pmow</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/User_talk:Pmow"/>
				<updated>2008-07-24T15:50:05Z</updated>
		
		<summary type="html">&lt;p&gt;Pmow: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Hi. Thanks for all of your contributions; do you want to create a user page? [[User:Simsong|Simsong]] 04:38, 24 July 2008 (UTC)&lt;br /&gt;
&lt;br /&gt;
done and done!&lt;/div&gt;</summary>
		<author><name>Pmow</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/User:Pmow</id>
		<title>User:Pmow</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/User:Pmow"/>
				<updated>2008-07-24T15:48:54Z</updated>
		
		<summary type="html">&lt;p&gt;Pmow: bio/contact info&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Meatspace Name==&lt;br /&gt;
Gabriel Campos&lt;br /&gt;
&lt;br /&gt;
==Location==&lt;br /&gt;
[http://www.rachlin.com/serviceareas/litigation_forensic.htm Rachlin LLP]&lt;br /&gt;
&lt;br /&gt;
[http://www.google.com/maps?f=q&amp;amp;hl=en&amp;amp;geocode=&amp;amp;q=Miami,+FL&amp;amp;ie=UTF8&amp;amp;layer=x&amp;amp;ll=25.760938,-80.237274&amp;amp;spn=0.44834,0.683899&amp;amp;z=11 Miami, Florida]&lt;br /&gt;
&lt;br /&gt;
==Contact==&lt;br /&gt;
[mailto:gcampos@rachlin.com gcampos@rachlin.com]&lt;/div&gt;</summary>
		<author><name>Pmow</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/List_of_Windows_MRU_Locations</id>
		<title>List of Windows MRU Locations</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/List_of_Windows_MRU_Locations"/>
				<updated>2008-07-23T17:23:02Z</updated>
		
		<summary type="html">&lt;p&gt;Pmow: Added more sources&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Common==&lt;br /&gt;
'''Regedit - Last accessed key''' 	&lt;br /&gt;
:Software\Microsoft\Windows\CurrentVersion\Applets\Regedit&lt;br /&gt;
'''Regedit - Favorites''' 	&lt;br /&gt;
:Software\Microsoft\Windows\CurrentVersion\Applets\Regedit\Favorites&lt;br /&gt;
'''MSPaint - Recent Files''' 	&lt;br /&gt;
:Software\Microsoft\Windows\CurrentVersion\Applets\Paint\Recent File List&lt;br /&gt;
'''Wordpad - Recent Files 	'''&lt;br /&gt;
:Software\Microsoft\Windows\CurrentVersion\Applets\Wordpad\Recent File List&lt;br /&gt;
'''Common Dialog - Open''' 	&lt;br /&gt;
:Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedMRU&lt;br /&gt;
'''Common Dialog - Save As 	'''&lt;br /&gt;
:Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU&lt;br /&gt;
'''WMP8 XP - Recent Files''' 	&lt;br /&gt;
:Software\Microsoft\MediaPlayer\Player\RecentFileList&lt;br /&gt;
'''WMP 8 XP - Recent URLs 	'''&lt;br /&gt;
:Software\Microsoft\MediaPlayer\Player\RecentURLList&lt;br /&gt;
'''OE6 Stationery list 1 - New Mail''' 	&lt;br /&gt;
:Identities\{C19958F2-22F3-4C6A-9AE0-12049CE0706F}\Software\Microsoft\Outlook Express\5.0\Recent Stationery List (ID=example)&lt;br /&gt;
'''OE 6 Stationery list 2 - New Mail''' 	&lt;br /&gt;
:Identities\{C19958F2-22F3-4C6A-9AE0-12049CE0706F}\Software\Microsoft\Outlook Express\5.0\Recent Stationery Wide List (ID=example)&lt;br /&gt;
'''Map Network Drives'''&lt;br /&gt;
:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Map Network Drive MRU&lt;br /&gt;
&lt;br /&gt;
==Windows 2000/XP==&lt;br /&gt;
'''''Recently Used Files'''''&lt;br /&gt;
:C:\Documents and Settings\User\Recent&lt;br /&gt;
'''XP Search Files'''&lt;br /&gt;
:Software\Microsoft\Search Assistant\ACMru\5603&lt;br /&gt;
'''Internet Search Assistant 	'''&lt;br /&gt;
:Software\Microsoft\Search Assistant\ACMru\5001&lt;br /&gt;
'''Printers, Computers and People'''&lt;br /&gt;
:Software\Microsoft\Search Assistant\ACMru\5647&lt;br /&gt;
'''XP Start Menu - Recent'''&lt;br /&gt;
:Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs&lt;br /&gt;
'''Remote Desktop - Connect'''&lt;br /&gt;
:Software\Microsoft\Terminal Server Client\Default [MRUnumber]&lt;br /&gt;
'''Run dialog box'''&lt;br /&gt;
:Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU&lt;br /&gt;
&lt;br /&gt;
==Windows ME, 98, and 95==&lt;br /&gt;
'''Doc Find Spec MRU'''&lt;br /&gt;
:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Doc Find Spec MRU&lt;br /&gt;
'''Find Computer'''&lt;br /&gt;
:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FindComputerMRU&lt;br /&gt;
'''Printer Ports'''&lt;br /&gt;
:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\PrnPortsMRU&lt;br /&gt;
'''Run'''&lt;br /&gt;
:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU&lt;br /&gt;
'''Window Size/Position'''&lt;br /&gt;
:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU&lt;br /&gt;
&lt;br /&gt;
==Microsoft Office 2000==&lt;br /&gt;
'''Winword - Open'''&lt;br /&gt;
:Software\Microsoft\Office\9.0\Common\Open Find\Microsoft Word\Settings\Open\File Name MRU&lt;br /&gt;
'''Winword - Save As''' 	&lt;br /&gt;
:Software\Microsoft\Office\9.0\Common\Open Find\Microsoft Word\Settings\Save As\File Name MRU&lt;br /&gt;
'''Winword - Recent Files'''&lt;br /&gt;
:Software\Microsoft\Office\9.0\Word\Data&lt;br /&gt;
'''Excel - Open''' &lt;br /&gt;
:Software\Microsoft\Office\9.0\Common\Open Find\Microsoft Excel\Settings\Open\File Name MRU&lt;br /&gt;
'''Excel - Save As''' 	&lt;br /&gt;
:Software\Microsoft\Office\9.0\Common\Open Find\Microsoft Excel\Settings\Save As\File Name MRU&lt;br /&gt;
'''Excel  - Recent Files''' 	&lt;br /&gt;
:Software\Microsoft\Office\9.0\Excel\Recent Files&lt;br /&gt;
'''Frontpage - Open''' 	&lt;br /&gt;
:Software\Microsoft\Office\9.0\Common\Open Find\Microsoft FrontPage\Settings\Open File\File Name MRU&lt;br /&gt;
'''Frontpage - Save As''' 	&lt;br /&gt;
:Software\Microsoft\Office\9.0\Common\Open Find\Microsoft FrontPage\Settings\Save As\File Name MRU&lt;br /&gt;
'''Frontpage - Recent lists''' 	&lt;br /&gt;
:Software\Microsoft\FrontPage\Explorer\FrontPage Explorer\Recent File List&lt;br /&gt;
:Software\Microsoft\FrontPage\Explorer\FrontPage Explorer\Recent Page List&lt;br /&gt;
:Software\Microsoft\FrontPage\Explorer\FrontPage Explorer\Recent Web List&lt;br /&gt;
:Software\Microsoft\FrontPage\Explorer\FrontPage Explorer\Recently Created Servers&lt;br /&gt;
:Software\Microsoft\FrontPage\Editor\Recently Used URLs&lt;br /&gt;
'''PowerPoint - Open''' 	&lt;br /&gt;
:Software\Microsoft\Office\9.0\Common\Open Find\Microsoft PowerPoint\Settings\Open\File Name MRU&lt;br /&gt;
'''PowerPoint - Save As''' 	&lt;br /&gt;
:Software\Microsoft\Office\9.0\Common\Open Find\Microsoft PowerPoint\Settings\Save As\File Name MRU&lt;br /&gt;
'''PowerPoint - Recent Files''' 	&lt;br /&gt;
:Software\Microsoft\Office\9.0\PowerPoint\Recent File List&lt;br /&gt;
'''Access - Open''' 	&lt;br /&gt;
:Software\Microsoft\Office\9.0\Common\Open Find\Microsoft Access\Settings\Open\File Name MRU&lt;br /&gt;
'''Access - Filename MRU''' 	&lt;br /&gt;
:Software\Microsoft\Office\9.0\Common\Open Find\Microsoft Access\Settings\File New Database\File Name MRU&lt;br /&gt;
:Software\Microsoft\Office\9.0\Access\Settings&lt;br /&gt;
&lt;br /&gt;
==Internet Explorer==&lt;br /&gt;
'''Recently Entered Addresses'''&lt;br /&gt;
:USERNAME\software\microsoft\internet explorer\typedurls&lt;br /&gt;
'''Last Directory Saved To'''&lt;br /&gt;
:USERNAME\software\microsoft\internet explorer&lt;br /&gt;
&lt;br /&gt;
==Adobe==&lt;br /&gt;
'''Media Browser'''&lt;br /&gt;
:HKEY_CURRENT_USER\Software\Adobe\MediaBrowser\MRU&lt;br /&gt;
'''Acrobat 5.0 Full'''&lt;br /&gt;
:HKEY_CURRENT_USER\Software\ADOBE\Adobe Acrobat\5.0\AVGeneral\cRecentFiles&lt;br /&gt;
'''Acrobat Reader 5.0'''&lt;br /&gt;
:HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\5.0\AVGeneral\cRecentFiles&lt;br /&gt;
'''Acrobat 8.0 Standard'''&lt;br /&gt;
:HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\8.0\AVGeneral\cRecentFiles [[User:Pmow|Pmow]] 16:14, 23 July 2008 (UTC)&lt;br /&gt;
&lt;br /&gt;
==Windows Explorer==&lt;br /&gt;
'''List of Recent Programs Opened'''&lt;br /&gt;
:HKEY_USERS\USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedMRU&lt;br /&gt;
'''Save Locations by Filetype'''&lt;br /&gt;
:HKEY_USERS\USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU&lt;br /&gt;
'''Most Recent Application's Use of DirectX'''&lt;br /&gt;
:software\microsoft\direct3d\mostrecentapplication&lt;br /&gt;
'''List of Recent Files Opened, by Filetype'''&lt;br /&gt;
:USERNAME\software\microsoft\windows\currentversion\explorer\recentdocs&lt;br /&gt;
&lt;br /&gt;
==Kazaa==&lt;br /&gt;
'''Recent Search List'''&lt;br /&gt;
:USERNAME\software\kazaa\search&lt;br /&gt;
&lt;br /&gt;
==Registry Editor==&lt;br /&gt;
'''Last Key Accessed'''&lt;br /&gt;
:USERNAME\software\microsoft\windows\currentversion\applets\regedit&lt;br /&gt;
==Sources==&lt;br /&gt;
&lt;br /&gt;
[http://www.daniweb.com/tutorials/tutorial66079.html Registry MRU Locations]&lt;br /&gt;
&lt;br /&gt;
[http://support.microsoft.com/kb/142298 How to Clear the Windows Explorer MRU Lists]&lt;br /&gt;
&lt;br /&gt;
[http://209.85.215.104/search?q=cache:ztqvo2Bfk9UJ:www.daniweb.com/forums/thread13426.html+adobe+MRU+location&amp;amp;hl=en&amp;amp;ct=clnk&amp;amp;cd=2&amp;amp;gl=us&amp;amp;client=firefox-a What are MRU files and why are they a security risk?]&lt;br /&gt;
&lt;br /&gt;
[http://www.windowsbbs.com/windows-2000/47519-removing-mru-list-mapped-network-drives.html Removing MRU List from Mapped Network Drives]&lt;/div&gt;</summary>
		<author><name>Pmow</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/List_of_Windows_MRU_Locations</id>
		<title>List of Windows MRU Locations</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/List_of_Windows_MRU_Locations"/>
				<updated>2008-07-23T16:14:01Z</updated>
		
		<summary type="html">&lt;p&gt;Pmow: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Common==&lt;br /&gt;
'''Regedit - Last accessed key''' 	&lt;br /&gt;
:Software\Microsoft\Windows\CurrentVersion\Applets\Regedit&lt;br /&gt;
'''Regedit - Favorites''' 	&lt;br /&gt;
:Software\Microsoft\Windows\CurrentVersion\Applets\Regedit\Favorites&lt;br /&gt;
'''MSPaint - Recent Files''' 	&lt;br /&gt;
:Software\Microsoft\Windows\CurrentVersion\Applets\Paint\Recent File List&lt;br /&gt;
'''Wordpad - Recent Files 	'''&lt;br /&gt;
:Software\Microsoft\Windows\CurrentVersion\Applets\Wordpad\Recent File List&lt;br /&gt;
'''Common Dialog - Open''' 	&lt;br /&gt;
:Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedMRU&lt;br /&gt;
'''Common Dialog - Save As 	'''&lt;br /&gt;
:Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU&lt;br /&gt;
'''WMP8 XP - Recent Files''' 	&lt;br /&gt;
:Software\Microsoft\MediaPlayer\Player\RecentFileList&lt;br /&gt;
'''WMP 8 XP - Recent URLs 	'''&lt;br /&gt;
:Software\Microsoft\MediaPlayer\Player\RecentURLList&lt;br /&gt;
'''OE6 Stationery list 1 - New Mail''' 	&lt;br /&gt;
:Identities\{C19958F2-22F3-4C6A-9AE0-12049CE0706F}\Software\Microsoft\Outlook Express\5.0\Recent Stationery List (ID=example)&lt;br /&gt;
'''OE 6 Stationery list 2 - New Mail''' 	&lt;br /&gt;
:Identities\{C19958F2-22F3-4C6A-9AE0-12049CE0706F}\Software\Microsoft\Outlook Express\5.0\Recent Stationery Wide List (ID=example)&lt;br /&gt;
&lt;br /&gt;
==Windows 2000/XP==&lt;br /&gt;
'''XP Search Files'''&lt;br /&gt;
:Software\Microsoft\Search Assistant\ACMru\5603&lt;br /&gt;
'''Internet Search Assistant 	'''&lt;br /&gt;
:Software\Microsoft\Search Assistant\ACMru\5001&lt;br /&gt;
'''Printers, Computers and People'''&lt;br /&gt;
:Software\Microsoft\Search Assistant\ACMru\5647&lt;br /&gt;
'''XP Start Menu - Recent'''&lt;br /&gt;
:Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs&lt;br /&gt;
'''Remote Desktop - Connect'''&lt;br /&gt;
:Software\Microsoft\Terminal Server Client\Default [MRUnumber]&lt;br /&gt;
'''Run dialog box'''&lt;br /&gt;
:Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU&lt;br /&gt;
&lt;br /&gt;
==Windows ME, 98, and 95==&lt;br /&gt;
'''Doc Find Spec MRU'''&lt;br /&gt;
:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Doc Find Spec MRU&lt;br /&gt;
'''Find Computer'''&lt;br /&gt;
:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FindComputerMRU&lt;br /&gt;
'''Printer Ports'''&lt;br /&gt;
:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\PrnPortsMRU&lt;br /&gt;
'''Run'''&lt;br /&gt;
:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU&lt;br /&gt;
'''Window Size/Position'''&lt;br /&gt;
:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU&lt;br /&gt;
&lt;br /&gt;
==Microsoft Office 2000==&lt;br /&gt;
'''Winword - Open'''&lt;br /&gt;
:Software\Microsoft\Office\9.0\Common\Open Find\Microsoft Word\Settings\Open\File Name MRU&lt;br /&gt;
'''Winword - Save As''' 	&lt;br /&gt;
:Software\Microsoft\Office\9.0\Common\Open Find\Microsoft Word\Settings\Save As\File Name MRU&lt;br /&gt;
'''Winword - Recent Files'''&lt;br /&gt;
:Software\Microsoft\Office\9.0\Word\Data&lt;br /&gt;
'''Excel - Open''' &lt;br /&gt;
:Software\Microsoft\Office\9.0\Common\Open Find\Microsoft Excel\Settings\Open\File Name MRU&lt;br /&gt;
'''Excel - Save As''' 	&lt;br /&gt;
:Software\Microsoft\Office\9.0\Common\Open Find\Microsoft Excel\Settings\Save As\File Name MRU&lt;br /&gt;
'''Excel  - Recent Files''' 	&lt;br /&gt;
:Software\Microsoft\Office\9.0\Excel\Recent Files&lt;br /&gt;
'''Frontpage - Open''' 	&lt;br /&gt;
:Software\Microsoft\Office\9.0\Common\Open Find\Microsoft FrontPage\Settings\Open File\File Name MRU&lt;br /&gt;
'''Frontpage - Save As''' 	&lt;br /&gt;
:Software\Microsoft\Office\9.0\Common\Open Find\Microsoft FrontPage\Settings\Save As\File Name MRU&lt;br /&gt;
'''Frontpage - Recent lists''' 	&lt;br /&gt;
:Software\Microsoft\FrontPage\Explorer\FrontPage Explorer\Recent File List&lt;br /&gt;
:Software\Microsoft\FrontPage\Explorer\FrontPage Explorer\Recent Page List&lt;br /&gt;
:Software\Microsoft\FrontPage\Explorer\FrontPage Explorer\Recent Web List&lt;br /&gt;
:Software\Microsoft\FrontPage\Explorer\FrontPage Explorer\Recently Created Servers&lt;br /&gt;
:Software\Microsoft\FrontPage\Editor\Recently Used URLs&lt;br /&gt;
'''PowerPoint - Open''' 	&lt;br /&gt;
:Software\Microsoft\Office\9.0\Common\Open Find\Microsoft PowerPoint\Settings\Open\File Name MRU&lt;br /&gt;
'''PowerPoint - Save As''' 	&lt;br /&gt;
:Software\Microsoft\Office\9.0\Common\Open Find\Microsoft PowerPoint\Settings\Save As\File Name MRU&lt;br /&gt;
'''PowerPoint - Recent Files''' 	&lt;br /&gt;
:Software\Microsoft\Office\9.0\PowerPoint\Recent File List&lt;br /&gt;
'''Access - Open''' 	&lt;br /&gt;
:Software\Microsoft\Office\9.0\Common\Open Find\Microsoft Access\Settings\Open\File Name MRU&lt;br /&gt;
'''Access - Filename MRU''' 	&lt;br /&gt;
:Software\Microsoft\Office\9.0\Common\Open Find\Microsoft Access\Settings\File New Database\File Name MRU&lt;br /&gt;
:Software\Microsoft\Office\9.0\Access\Settings&lt;br /&gt;
&lt;br /&gt;
==Internet Explorer==&lt;br /&gt;
'''Recently Entered Addresses'''&lt;br /&gt;
:USERNAME\software\microsoft\internet explorer\typedurls&lt;br /&gt;
'''Last Directory Saved To'''&lt;br /&gt;
:USERNAME\software\microsoft\internet explorer&lt;br /&gt;
&lt;br /&gt;
==Adobe==&lt;br /&gt;
'''Media Browser'''&lt;br /&gt;
:HKEY_CURRENT_USER\Software\Adobe\MediaBrowser\MRU&lt;br /&gt;
'''Acrobat 5.0 Full'''&lt;br /&gt;
:HKEY_CURRENT_USER\Software\ADOBE\Adobe Acrobat\5.0\AVGeneral\cRecentFiles&lt;br /&gt;
'''Acrobat Reader 5.0'''&lt;br /&gt;
:HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\5.0\AVGeneral\cRecentFiles&lt;br /&gt;
'''Acrobat 8.0 Standard'''&lt;br /&gt;
:HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\8.0\AVGeneral\cRecentFiles [[User:Pmow|Pmow]] 16:14, 23 July 2008 (UTC)&lt;br /&gt;
&lt;br /&gt;
==Windows Explorer==&lt;br /&gt;
'''List of Recent Programs Opened'''&lt;br /&gt;
:HKEY_USERS\USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedMRU&lt;br /&gt;
'''Save Locations by Filetype'''&lt;br /&gt;
:HKEY_USERS\USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU&lt;br /&gt;
'''Most Recent Application's Use of DirectX'''&lt;br /&gt;
:software\microsoft\direct3d\mostrecentapplication&lt;br /&gt;
'''List of Recent Files Opened, by Filetype'''&lt;br /&gt;
:USERNAME\software\microsoft\windows\currentversion\explorer\recentdocs&lt;br /&gt;
&lt;br /&gt;
==Kazaa==&lt;br /&gt;
'''Recent Search List'''&lt;br /&gt;
:USERNAME\software\kazaa\search&lt;br /&gt;
&lt;br /&gt;
==Registry Editor==&lt;br /&gt;
'''Last Key Accessed'''&lt;br /&gt;
:USERNAME\software\microsoft\windows\currentversion\applets\regedit&lt;br /&gt;
==Sources==&lt;br /&gt;
&lt;br /&gt;
[http://www.daniweb.com/tutorials/tutorial66079.html Registry MRU Locations]&lt;br /&gt;
&lt;br /&gt;
[http://support.microsoft.com/kb/142298 How to Clear the Windows Explorer MRU Lists]&lt;/div&gt;</summary>
		<author><name>Pmow</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Most_Recently_Used</id>
		<title>Most Recently Used</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Most_Recently_Used"/>
				<updated>2008-07-23T15:22:19Z</updated>
		
		<summary type="html">&lt;p&gt;Pmow: trying to redirect&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;#REDIRECT [[MRU]]&lt;/div&gt;</summary>
		<author><name>Pmow</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/List_of_Windows_MRU_Locations</id>
		<title>List of Windows MRU Locations</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/List_of_Windows_MRU_Locations"/>
				<updated>2008-07-23T15:15:02Z</updated>
		
		<summary type="html">&lt;p&gt;Pmow: New page: ==Common== '''Regedit - Last accessed key''' 	 :Software\Microsoft\Windows\CurrentVersion\Applets\Regedit '''Regedit - Favorites''' 	 :Software\Microsoft\Windows\CurrentVersion\Applets\Reg...&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Common==&lt;br /&gt;
'''Regedit - Last accessed key''' 	&lt;br /&gt;
:Software\Microsoft\Windows\CurrentVersion\Applets\Regedit&lt;br /&gt;
'''Regedit - Favorites''' 	&lt;br /&gt;
:Software\Microsoft\Windows\CurrentVersion\Applets\Regedit\Favorites&lt;br /&gt;
'''MSPaint - Recent Files''' 	&lt;br /&gt;
:Software\Microsoft\Windows\CurrentVersion\Applets\Paint\Recent File List&lt;br /&gt;
'''Wordpad - Recent Files 	'''&lt;br /&gt;
:Software\Microsoft\Windows\CurrentVersion\Applets\Wordpad\Recent File List&lt;br /&gt;
'''Common Dialog - Open''' 	&lt;br /&gt;
:Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedMRU&lt;br /&gt;
'''Common Dialog - Save As 	'''&lt;br /&gt;
:Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU&lt;br /&gt;
'''WMP8 XP - Recent Files''' 	&lt;br /&gt;
:Software\Microsoft\MediaPlayer\Player\RecentFileList&lt;br /&gt;
'''WMP 8 XP - Recent URLs 	'''&lt;br /&gt;
:Software\Microsoft\MediaPlayer\Player\RecentURLList&lt;br /&gt;
'''OE6 Stationery list 1 - New Mail''' 	&lt;br /&gt;
:Identities\{C19958F2-22F3-4C6A-9AE0-12049CE0706F}\Software\Microsoft\Outlook Express\5.0\Recent Stationery List (ID=example)&lt;br /&gt;
'''OE 6 Stationery list 2 - New Mail''' 	&lt;br /&gt;
:Identities\{C19958F2-22F3-4C6A-9AE0-12049CE0706F}\Software\Microsoft\Outlook Express\5.0\Recent Stationery Wide List (ID=example)&lt;br /&gt;
&lt;br /&gt;
==Windows 2000/XP==&lt;br /&gt;
'''XP Search Files'''&lt;br /&gt;
:Software\Microsoft\Search Assistant\ACMru\5603&lt;br /&gt;
'''Internet Search Assistant 	'''&lt;br /&gt;
:Software\Microsoft\Search Assistant\ACMru\5001&lt;br /&gt;
'''Printers, Computers and People'''&lt;br /&gt;
:Software\Microsoft\Search Assistant\ACMru\5647&lt;br /&gt;
'''XP Start Menu - Recent'''&lt;br /&gt;
:Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs&lt;br /&gt;
'''Remote Desktop - Connect'''&lt;br /&gt;
:Software\Microsoft\Terminal Server Client\Default [MRUnumber]&lt;br /&gt;
'''Run dialog box'''&lt;br /&gt;
:Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU&lt;br /&gt;
&lt;br /&gt;
==Windows ME, 98, and 95==&lt;br /&gt;
'''Doc Find Spec MRU'''&lt;br /&gt;
:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Doc Find Spec MRU&lt;br /&gt;
'''Find Computer'''&lt;br /&gt;
:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FindComputerMRU&lt;br /&gt;
'''Printer Ports'''&lt;br /&gt;
:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\PrnPortsMRU&lt;br /&gt;
'''Run'''&lt;br /&gt;
:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU&lt;br /&gt;
'''Window Size/Position'''&lt;br /&gt;
:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU&lt;br /&gt;
&lt;br /&gt;
==Microsoft Office 2000==&lt;br /&gt;
'''Winword - Open'''&lt;br /&gt;
:Software\Microsoft\Office\9.0\Common\Open Find\Microsoft Word\Settings\Open\File Name MRU&lt;br /&gt;
'''Winword - Save As''' 	&lt;br /&gt;
:Software\Microsoft\Office\9.0\Common\Open Find\Microsoft Word\Settings\Save As\File Name MRU&lt;br /&gt;
'''Winword - Recent Files'''&lt;br /&gt;
:Software\Microsoft\Office\9.0\Word\Data&lt;br /&gt;
'''Excel - Open''' &lt;br /&gt;
:Software\Microsoft\Office\9.0\Common\Open Find\Microsoft Excel\Settings\Open\File Name MRU&lt;br /&gt;
'''Excel - Save As''' 	&lt;br /&gt;
:Software\Microsoft\Office\9.0\Common\Open Find\Microsoft Excel\Settings\Save As\File Name MRU&lt;br /&gt;
'''Excel  - Recent Files''' 	&lt;br /&gt;
:Software\Microsoft\Office\9.0\Excel\Recent Files&lt;br /&gt;
'''Frontpage - Open''' 	&lt;br /&gt;
:Software\Microsoft\Office\9.0\Common\Open Find\Microsoft FrontPage\Settings\Open File\File Name MRU&lt;br /&gt;
'''Frontpage - Save As''' 	&lt;br /&gt;
:Software\Microsoft\Office\9.0\Common\Open Find\Microsoft FrontPage\Settings\Save As\File Name MRU&lt;br /&gt;
'''Frontpage - Recent lists''' 	&lt;br /&gt;
:Software\Microsoft\FrontPage\Explorer\FrontPage Explorer\Recent File List&lt;br /&gt;
:Software\Microsoft\FrontPage\Explorer\FrontPage Explorer\Recent Page List&lt;br /&gt;
:Software\Microsoft\FrontPage\Explorer\FrontPage Explorer\Recent Web List&lt;br /&gt;
:Software\Microsoft\FrontPage\Explorer\FrontPage Explorer\Recently Created Servers&lt;br /&gt;
:Software\Microsoft\FrontPage\Editor\Recently Used URLs&lt;br /&gt;
'''PowerPoint - Open''' 	&lt;br /&gt;
:Software\Microsoft\Office\9.0\Common\Open Find\Microsoft PowerPoint\Settings\Open\File Name MRU&lt;br /&gt;
'''PowerPoint - Save As''' 	&lt;br /&gt;
:Software\Microsoft\Office\9.0\Common\Open Find\Microsoft PowerPoint\Settings\Save As\File Name MRU&lt;br /&gt;
'''PowerPoint - Recent Files''' 	&lt;br /&gt;
:Software\Microsoft\Office\9.0\PowerPoint\Recent File List&lt;br /&gt;
'''Access - Open''' 	&lt;br /&gt;
:Software\Microsoft\Office\9.0\Common\Open Find\Microsoft Access\Settings\Open\File Name MRU&lt;br /&gt;
'''Access - Filename MRU''' 	&lt;br /&gt;
:Software\Microsoft\Office\9.0\Common\Open Find\Microsoft Access\Settings\File New Database\File Name MRU&lt;br /&gt;
:Software\Microsoft\Office\9.0\Access\Settings&lt;br /&gt;
&lt;br /&gt;
==Sources==&lt;br /&gt;
&lt;br /&gt;
[http://www.daniweb.com/tutorials/tutorial66079.html Registry MRU Locations]&lt;br /&gt;
&lt;br /&gt;
[http://support.microsoft.com/kb/142298 How to Clear the Windows Explorer MRU Lists]&lt;/div&gt;</summary>
		<author><name>Pmow</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/MRU</id>
		<title>MRU</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/MRU"/>
				<updated>2008-07-23T14:29:23Z</updated>
		
		<summary type="html">&lt;p&gt;Pmow: created&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Most Recently Used=&lt;br /&gt;
Most Recently Used (MRU) is a term used in computing to refer to the list of programs or documents that were last accessed. It is a feature of convenience allowing users to quickly see and access the last few used files and documents, but could also be considered bad in terms of privacy.&lt;br /&gt;
&lt;br /&gt;
==See Also==&lt;br /&gt;
[[List of Windows MRU Locations]]&lt;/div&gt;</summary>
		<author><name>Pmow</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/The_Sleuth_Kit</id>
		<title>The Sleuth Kit</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/The_Sleuth_Kit"/>
				<updated>2008-07-17T20:50:23Z</updated>
		
		<summary type="html">&lt;p&gt;Pmow: genre changed to Analysis from Disk file systems&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Infobox_Software |&lt;br /&gt;
  name = The Sleuth Kit |&lt;br /&gt;
  maintainer = [[Brian Carrier]] |&lt;br /&gt;
  os = {{Linux}}, {{FreeBSD}}, {{OpenBSD}}, {{Mac OS X}}, {{SunOS}} |&lt;br /&gt;
  genre = {{Analysis}} |&lt;br /&gt;
  license = {{IBM Open Source License}}, {{Common Public License}}, {{GPL}} |&lt;br /&gt;
  website = [http://www.sleuthkit.org/ sleuthkit.org] |&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
'''The Sleuth Kit''' ('''TSK''') is a collection of [[UNIX]]-based command line tools that allow you to investigate a computer. The current focus of the tools is the file and volume systems and TSK supports [[FAT]], [[Ext2]]/[[Ext3|3]], [[NTFS]], [[UFS1]], and [[UFS2]] [[file system]]s.&lt;br /&gt;
&lt;br /&gt;
[[Autopsy]] is a frontend for TSK which allows browser-based access to the TSK tools.&lt;br /&gt;
 &lt;br /&gt;
=Features=&lt;br /&gt;
&lt;br /&gt;
The Sleuth Kit is arranged in layers. There is a ''data layer'' which is concerned with how information is stored on a disk and a ''metadata layer'' which is considered with information such as [[inode]]s and [[directory|directories]]. The commands that deal with the data layer are prefixed with the letter ''d'', which the commands that deal with the metadata layer are prefixed with the letter ''i''.&lt;br /&gt;
&lt;br /&gt;
Some of the commands in Sleuth Kit are:&lt;br /&gt;
&lt;br /&gt;
; dcat&lt;br /&gt;
: Views the contents of a [[block]].&lt;br /&gt;
&lt;br /&gt;
; dls&lt;br /&gt;
: Lists [[unallocated block]]s. Makes keyword searches more efficient. Gets a list of unallocated blocks.&lt;br /&gt;
&lt;br /&gt;
; dcalc&lt;br /&gt;
: Tells you where an unallocated blocks are.&lt;br /&gt;
&lt;br /&gt;
; dstat&lt;br /&gt;
: Details about a given block.&lt;br /&gt;
&lt;br /&gt;
; icat&lt;br /&gt;
: View contents of a file given its inode value or [[cluster number]]. Doesn't list directories, lists the contents.&lt;br /&gt;
&lt;br /&gt;
; ils&lt;br /&gt;
: Lists the files extents on a disk.&lt;br /&gt;
&lt;br /&gt;
; istat&lt;br /&gt;
: Information about an inode number.&lt;br /&gt;
&lt;br /&gt;
==File Systems Understood==&lt;br /&gt;
&lt;br /&gt;
* [[NTFS]]&lt;br /&gt;
* [[FAT]]&lt;br /&gt;
* [[EXT2]], [[EXT3]]&lt;br /&gt;
* [[UFS1]], [[UFS2]]&lt;br /&gt;
 &lt;br /&gt;
==File Search Facilities==&lt;br /&gt;
&lt;br /&gt;
* Lists allocated and unallocated files.&lt;br /&gt;
* Lists and sorts by file type.&lt;br /&gt;
* Shows a time time of creation and change.&lt;br /&gt;
 &lt;br /&gt;
==Historical Reconstruction==&lt;br /&gt;
 &lt;br /&gt;
==Searching Abilities==&lt;br /&gt;
 &lt;br /&gt;
* Searches for keywords.&lt;br /&gt;
* Builds an index.&lt;br /&gt;
&lt;br /&gt;
==Hash Databases==&lt;br /&gt;
&lt;br /&gt;
* Uses [[MD5]] or [[SHA1]].&lt;br /&gt;
* Interfaces with [[NIST NSRL]], [[Hashkeeper]] and customer databases.&lt;br /&gt;
 &lt;br /&gt;
==Evidence Collection Features==&lt;br /&gt;
 &lt;br /&gt;
* Tracks forensic activity.&lt;br /&gt;
&lt;br /&gt;
=History=&lt;br /&gt;
&lt;br /&gt;
==License Notes==&lt;br /&gt;
&lt;br /&gt;
Is it commercial or open source? Are there other licensing options?&lt;br /&gt;
&lt;br /&gt;
= External Links =&lt;br /&gt;
&lt;br /&gt;
* [http://www.sleuthkit.org/autopsy/desc.php Autopsy website]&lt;br /&gt;
 &lt;br /&gt;
==External Reviews==&lt;/div&gt;</summary>
		<author><name>Pmow</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Reiserfs</id>
		<title>Reiserfs</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Reiserfs"/>
				<updated>2008-07-17T20:47:44Z</updated>
		
		<summary type="html">&lt;p&gt;Pmow: Categorized&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Detecting ReiserFS in a forensics environment ==&lt;br /&gt;
&lt;br /&gt;
[[Image:Superblock.png]]&lt;br /&gt;
&lt;br /&gt;
Note: These are in [http://en.wikipedia.org/wiki/Little_endian little-endian] format. [[User:Pmow|Pmow]] 18:21, 17 July 2008 (UTC)&lt;br /&gt;
&amp;lt;table border=&amp;quot;0&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;th&amp;gt; '''Name''' &amp;lt;/th&amp;gt;&lt;br /&gt;
&lt;br /&gt;
        &amp;lt;th&amp;gt; Size &amp;lt;/th&amp;gt;&lt;br /&gt;
        &amp;lt;th&amp;gt; Description &amp;lt;/th&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Block count &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  4 &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
        &amp;lt;td&amp;gt;  The number of blocks in the partition &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Free blocks &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  4 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  The number of free blocks in the partition &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Root block &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  4 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  The block number of the block containing the root node &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Journal block &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  4 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  The block number of the block containing the first journal node &amp;lt;!--&amp;lt;/tr--&amp;gt;&lt;br /&gt;
&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Journal device &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  4 &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
        &amp;lt;td&amp;gt;  Journal device number (not sure what for) &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Orig. journal size &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  4 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  Original journal size. Needed when using partition on systems with different default journal sizes.&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Journal trans. max &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  4 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  The maximum number of blocks in a transaction &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Journal magic &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  4 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  A random magic number &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Journal max batch &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  4 &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
        &amp;lt;td&amp;gt;  The maximum number of blocks in a transaction &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Journal max commit age &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  4 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  Time in seconds of how old an asynchronous commit can be &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Journal max trans. age &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  4 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  Time in seconds of how old a transaction can be &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Blocksize &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  2 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  The size in bytes of a block &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; OID max size &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  2 &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
        &amp;lt;td&amp;gt;  The maximum size of the object id array &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; OID current size &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  2 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  The current size of the object id array &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; State &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  2 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  State of the partition: valid (1) or error (2) &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Magic string &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  12 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  The reiserfs magic string, should be &amp;quot;ReIsEr2Fs&amp;quot; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Hash function code &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  4 &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
        &amp;lt;td&amp;gt;  The  hash function that is being used to sort names in a directory&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Tree Height &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  2 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  The current height of the disk tree &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Bitmap number &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  2 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  The amount of bitmap blocks needed to address each block of the file system&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Version &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  2 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  The reiserfs version number &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Reserved &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  2 &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
        &amp;lt;td&amp;gt;  &amp;amp;nbsp; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Inode Generation &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  4 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  Number of the current inode generation. &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The following is the start of the superblock of a 256MB reiserfs partition on an Intel based system:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/p&amp;gt;&amp;lt;pre&amp;gt;00000000 66 00 01 00 93 18 00 00 82 40 00 00 12 00 00 00  f........@......&lt;br /&gt;
00000010 00 00 00 00 00 20 00 00 00 04 00 00 ac 34 11 57  ..... ......¬4.W&lt;br /&gt;
00000020 84 03 00 00 1e 00 00 00 00 00 00 00 00 10 cc 03  ..............Ì.&lt;br /&gt;
00000030 08 00 02 00 52 65 49 73 45 72 32 46 73 00 00 00  ....ReIsEr2Fs...&lt;br /&gt;
00000040 03 00 00 00 04 00 03 00 02 00 00 00 dc 52 00 00  ............ÜR..&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Image:superblock_example.png]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;Block count: 65638&lt;br /&gt;
&amp;lt;br&amp;gt;Free blocks: 6291&lt;br /&gt;
&amp;lt;br&amp;gt;Root block: 16514&lt;br /&gt;
&amp;lt;br&amp;gt;Journal block: 18&lt;br /&gt;
&amp;lt;br&amp;gt;Journal device: 0&lt;br /&gt;
&amp;lt;br&amp;gt;Original journal size: 8192&lt;br /&gt;
&amp;lt;br&amp;gt;Journal trans. max: 1024&lt;br /&gt;
&amp;lt;br&amp;gt;Journal magic: 1460745388&lt;br /&gt;
&amp;lt;br&amp;gt;Journal max. batch: 900&lt;br /&gt;
&amp;lt;br&amp;gt;Journal max. commit age: 30&lt;br /&gt;
&amp;lt;br&amp;gt;Journal max. trans. age: 0&lt;br /&gt;
&amp;lt;br&amp;gt;Blocksize: 4096&lt;br /&gt;
&amp;lt;br&amp;gt;OID max. size: 972&lt;br /&gt;
&amp;lt;br&amp;gt;OID current size: 8&lt;br /&gt;
&amp;lt;br&amp;gt;State: 2 (error)&lt;br /&gt;
&amp;lt;br&amp;gt;Magic String: ReIsEr2Fs&lt;br /&gt;
&amp;lt;br&amp;gt;Hash function code: 3&lt;br /&gt;
&amp;lt;br&amp;gt;Tree height: 4&lt;br /&gt;
&amp;lt;br&amp;gt;Bitmap number: 3&lt;br /&gt;
&amp;lt;br&amp;gt;Version: 2&lt;br /&gt;
&amp;lt;br&amp;gt;Inode generation: 21212&lt;br /&gt;
&lt;br /&gt;
== External Links ==&lt;br /&gt;
* [http://en.wikipedia.org/wiki/Reiserfs ReiserFS on Wikipedia]&lt;br /&gt;
* [http://homes.cerias.purdue.edu/~florian/reiser/reiserfs.php The structure of the Reiser file system]&lt;br /&gt;
[[Category:Disk file systems]]&lt;/div&gt;</summary>
		<author><name>Pmow</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Training_Courses_and_Providers</id>
		<title>Training Courses and Providers</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Training_Courses_and_Providers"/>
				<updated>2008-07-17T20:31:22Z</updated>
		
		<summary type="html">&lt;p&gt;Pmow: Updated Applied Decryption, broken link to AccessData's pages.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This is the list of Scheduled Training Courses, referred to by [[Upcoming_events]].  Please refer to the instructions on the [[Upcoming_events]] page if you wish to edit this page.&lt;br /&gt;
&lt;br /&gt;
The Conference and Training List is provided by the American Academy of Forensic Sciences (AAFS) Digital and Multi-media Listserv.  &lt;br /&gt;
&amp;lt;i&amp;gt; (Subscribe by sending an email to listserv@lists.mitre.org with message body containing SUBSCRIBE AAFS-DIGITAL-MULTIMEDIA-LIST)&amp;lt;/i&amp;gt;&lt;br /&gt;
Requests for additions, deletions or corrections to this list may be sent by email to David Baker &amp;lt;i&amp;gt;(bakerd AT mitre.org)&amp;lt;/i&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;0&amp;quot; cellpadding=&amp;quot;2&amp;quot; cellspacing=&amp;quot;2&amp;quot; align=&amp;quot;top&amp;quot;&lt;br /&gt;
|- style=&amp;quot;background:#bfbfbf; font-weight: bold&amp;quot;&lt;br /&gt;
! Title&lt;br /&gt;
! Date/Location&lt;br /&gt;
! Website&lt;br /&gt;
! Limitation&lt;br /&gt;
|-&lt;br /&gt;
|Macintosh Forensic Survival Course (MFSC) &lt;br /&gt;
|Jun 30-Jul 04, Brisbane, Australia&lt;br /&gt;
|http://www.forwarddiscovery.com/shop/index.php?act=viewCat&amp;amp;catId=3&lt;br /&gt;
|Limited to Law Enforcement&lt;br /&gt;
|-&lt;br /&gt;
|EnCase&amp;amp;reg; Enterprise v6 - Phase II&lt;br /&gt;
|Jun 30-Jul 03, Los Angeles, CA&lt;br /&gt;
|http://www.guidancesoftware.com/training/course_schedule.aspx&lt;br /&gt;
|-&lt;br /&gt;
|AccessData&amp;amp;reg; BootCamp&lt;br /&gt;
|Jul 01-03, Manchester, United Kingdom&lt;br /&gt;
|http://www.accessdata.com/common/pagedetail.aspx?PageCode=train&lt;br /&gt;
|-&lt;br /&gt;
|BlackBag Intermediate MacIntosh Forensics&lt;br /&gt;
|Jul 07-11, Los Angeles, CA&lt;br /&gt;
|http://www.blackbagtech.com/products/training.htm&lt;br /&gt;
|Limited to Law Enforcement&lt;br /&gt;
|-&lt;br /&gt;
|Linux /Unix Security&lt;br /&gt;
|Jul 07-10, Reston, VA&lt;br /&gt;
|http://www.securityuniversity.net/classes_linux_sec.php&lt;br /&gt;
|-&lt;br /&gt;
|Certified Ethical Hacker/Qualified Security Hacker/Network Defender&lt;br /&gt;
|Jul 07-10, San Francisco, CA&lt;br /&gt;
|http://www.securityuniversity.net/classes_QSH.php&lt;br /&gt;
|-&lt;br /&gt;
|Computer Hacking Forensic Investigator CHFI Prep/QFE Qualified Forensics Expert&lt;br /&gt;
|Jul 12-16, Reston, VA&lt;br /&gt;
|http://www.securityuniversity.net/classes_CHFI_QFE.php&lt;br /&gt;
|-&lt;br /&gt;
|Mobile Device Investigations Program (MDIP)&lt;br /&gt;
|Jul 14-18, Glynco, GA&lt;br /&gt;
|http://www.fletc.gov/training/programs/computer-financial-investigations/technology-investigation&lt;br /&gt;
|Limited to Law Enforcement&lt;br /&gt;
|-&lt;br /&gt;
|AccessData&amp;amp;reg; Applied Decryption&lt;br /&gt;
|Jul 15-17, St Paul, MN&lt;br /&gt;
|http://guest.cvent.com/EVENTS/Info/Summary.aspx?e=ab0c756b-3cf8-4161-8a70-0c11c6f018fc&lt;br /&gt;
|-&lt;br /&gt;
|AccessData&amp;amp;reg; Windows Forensics&lt;br /&gt;
|Jul 15-17, London, United Kingdom&lt;br /&gt;
|http://www.accessdata.com/common/pagedetail.aspx?PageCode=train&lt;br /&gt;
|-&lt;br /&gt;
|WetStone- Steganography Investigator Training&lt;br /&gt;
|Jul 16-17, Online Training&lt;br /&gt;
|https://www.wetstonetech.com/trainings.html&lt;br /&gt;
|-&lt;br /&gt;
|Computer Network Investigations Training Program (CNITP)&lt;br /&gt;
|Jul 21-Aug 01, Glynco, GA&lt;br /&gt;
|http://www.fletc.gov/training/programs/computer-financial-investigations/technology-investigation&lt;br /&gt;
|Limited to Law Enforcement&lt;br /&gt;
|-&lt;br /&gt;
|Internet Investigations Training Program (IITP&lt;br /&gt;
|Jul 21-25, Glynco, GA&lt;br /&gt;
|http://www.fletc.gov/training/programs/computer-financial-investigations/technology-investigation&lt;br /&gt;
|Limited to Law Enforcement&lt;br /&gt;
|-&lt;br /&gt;
|BlackBag Intermediate MacIntosh Forensics&lt;br /&gt;
|Jul 21-25, San Jose, CA&lt;br /&gt;
|http://www.blackbagtech.com/products/training.htm	&lt;br /&gt;
|-&lt;br /&gt;
|EC-Council Certified Security Analyst/Qualified Security Analyst/Pen Testing Methods&lt;br /&gt;
|Jul 21-25, San Francisco, CA&lt;br /&gt;
|http://www.securityuniversity.net/classes_anti-hacking_pentest.php&lt;br /&gt;
|-&lt;br /&gt;
|Licensed Penetration Tester/Qualified Penetration Tester&lt;br /&gt;
|Jul 21-25, San Francisco, CA&lt;br /&gt;
|http://www.securityuniversity.net/classes_Licensed_Penetration_Tester.php&lt;br /&gt;
|-&lt;br /&gt;
|WetStone- Live Investigator Training&lt;br /&gt;
|Jul 22-23, Fairfax, VA&lt;br /&gt;
|https://www.wetstonetech.com/trainings.html&lt;br /&gt;
|-&lt;br /&gt;
|AccessData&amp;amp;reg; Windows Forensics&lt;br /&gt;
|Jul 22-24, St Louis, MO&lt;br /&gt;
|http://www.accessdata.com/common/pagedetail.aspx?PageCode=train&lt;br /&gt;
|-&lt;br /&gt;
|Computer Hacking Forensic Investigator CHFI Prep/Qualified Forensics Expert&lt;br /&gt;
|July 28-Aug 01, San Francisco, CA&lt;br /&gt;
|http://www.securityuniversity.net/classes_CHFI_QFE.php&lt;br /&gt;
|-&lt;br /&gt;
|ILook® Automated Forensic Application(ILook)&lt;br /&gt;
|Jul 28-Aug 01, St. Louis, MO&lt;br /&gt;
|http://www.nw3c.org/ocr/courses_desc.cfm&lt;br /&gt;
|Limited to Law Enforcement&lt;br /&gt;
|-&lt;br /&gt;
|Certified Wireless Network Administrator&lt;br /&gt;
|July 28-Aug 01, San Francisco, CA&lt;br /&gt;
|http://www.securityuniversity.net/www.classes_wireless_CWNA.php&lt;br /&gt;
|-&lt;br /&gt;
|Certified Wireless Network Admin/Wireless Security Professional Bootcamp&lt;br /&gt;
|July 29-Aug 07, San Francisco, CA&lt;br /&gt;
|http://www.securityuniversity.net/classes_wireless_bootcamp.php&lt;br /&gt;
|-&lt;br /&gt;
|WetStone- Steganography Investigator Training&lt;br /&gt;
|Aug 02-03, 04-05, Black Hat USA&lt;br /&gt;
|https://www.blackhat.com&lt;br /&gt;
|-&lt;br /&gt;
|WetStone- Live Investigator Training&lt;br /&gt;
|Aug 02-03, 04-05, Black Hat USA&lt;br /&gt;
|https://www.blackhat.com&lt;br /&gt;
|-&lt;br /&gt;
|WetStone- Hacking Investigator BootCamp&lt;br /&gt;
|Aug 02-05, Black Hat USA&lt;br /&gt;
|https://www.blackhat.com&lt;br /&gt;
|-&lt;br /&gt;
|Certified Wireless Security Professional CWSP&lt;br /&gt;
|Aug 04-07, San Francisco, CA&lt;br /&gt;
|http://www.securityuniversity.net/classes_wireless_CWSP.php&lt;br /&gt;
|-&lt;br /&gt;
|Linux /Unix Security&lt;br /&gt;
|Aug 04-07, Reston, VA&lt;br /&gt;
|http://www.securityuniversity.net/classes_linux_sec.php&lt;br /&gt;
|-&lt;br /&gt;
|Qualified Edge Protection: Firewalls, IPS, Spyware, Trojans and Viruses&lt;br /&gt;
|Aug 04-07, Reston, VA&lt;br /&gt;
|http://www.securityuniversity.net/classes_QEP.php&lt;br /&gt;
|-&lt;br /&gt;
|Macintosh Forensic Survival Course (MFSC) &lt;br /&gt;
|Aug 04-08, Huntington Beach, CA &lt;br /&gt;
|http://www.forwarddiscovery.com/shop/index.php?act=viewCat&amp;amp;catId=3&lt;br /&gt;
|-&lt;br /&gt;
|Certified Wireless Network Admin/Wireless Security Professional Bootcamp&lt;br /&gt;
|Aug 05-14, Reston, VA&lt;br /&gt;
|http://www.securityuniversity.net/classes_wireless_bootcamp.php&lt;br /&gt;
|-&lt;br /&gt;
|Certified Wireless Network Administrator&lt;br /&gt;
|Aug 05-08, Reston, VA&lt;br /&gt;
|http://www.securityuniversity.net/classes_wireless_CWNA.php&lt;br /&gt;
|-&lt;br /&gt;
|AccessData&amp;amp;reg; BootCamp&lt;br /&gt;
|Aug 05-07, London, United Kingdom&lt;br /&gt;
|http://www.accessdata.com/common/pagedetail.aspx?PageCode=train&lt;br /&gt;
|-&lt;br /&gt;
|AccessData&amp;amp;reg; Windows Forensics&lt;br /&gt;
|Aug 05-07, Louisville, KY&lt;br /&gt;
|http://www.accessdata.com/common/pagedetail.aspx?PageCode=train&lt;br /&gt;
|Limited to Law Enforcement&lt;br /&gt;
|-&lt;br /&gt;
|Certified Steganography Examiner™&lt;br /&gt;
|Aug 06-07, Huntington, WV&lt;br /&gt;
|http://www.sarc-wv.com/training/training_huntington.aspx&lt;br /&gt;
|-&lt;br /&gt;
|Certified Wireless Security Professional&lt;br /&gt;
|Aug 11-14, Reston, VA&lt;br /&gt;
|http://www.securityuniversity.net/classes_wireless_CWSP.php&lt;br /&gt;
|-&lt;br /&gt;
|X-Ways Forensics&lt;br /&gt;
|Aug 12-14, Wheaton, IL&lt;br /&gt;
|http://www.x-ways.net/training/chicago.html&lt;br /&gt;
|-&lt;br /&gt;
|AccessData&amp;amp;reg; Windows Forensics&lt;br /&gt;
|Aug 12-14, St Paul, MN&lt;br /&gt;
|http://www.accessdata.com/common/pagedetail.aspx?PageCode=train&lt;br /&gt;
|-&lt;br /&gt;
|AccessData&amp;amp;reg; BootCamp&lt;br /&gt;
|Aug 12-14, Albany, NY and New York City, NY&lt;br /&gt;
|http://www.accessdata.com/common/pagedetail.aspx?PageCode=train&lt;br /&gt;
|-&lt;br /&gt;
|Digital Evidence Acquisition Specialist Training Program (DEASTP)&lt;br /&gt;
|Aug 18-29, Glynco, GA&lt;br /&gt;
|http://www.fletc.gov/training/programs/computer-financial-investigations/technology-investigation&lt;br /&gt;
|Limited to Law Enforcement&lt;br /&gt;
|-&lt;br /&gt;
|BlackBag Introductory MacIntosh Forensics&lt;br /&gt;
|Aug 18-22, San Jose, CA&lt;br /&gt;
|http://www.blackbagtech.com/products/training.htm&lt;br /&gt;
|-&lt;br /&gt;
|WetStone- Steganography Investigator Training&lt;br /&gt;
|Aug 19-20, Fairfax, VA&lt;br /&gt;
|https://www.wetstonetech.com/trainings.html&lt;br /&gt;
|-&lt;br /&gt;
|AccessData&amp;amp;reg; BootCamp&lt;br /&gt;
|Aug 19-21, Manchester, United Kingdom&lt;br /&gt;
|http://www.accessdata.com/common/pagedetail.aspx?PageCode=train&lt;br /&gt;
|-&lt;br /&gt;
|WetStone- Live Investigator Training&lt;br /&gt;
|Aug 26-27, Vancouver BC&lt;br /&gt;
|https://www.wetstonetech.com/trainings.html&lt;br /&gt;
|-&lt;br /&gt;
|AccessData&amp;amp;reg; BootCamp&lt;br /&gt;
|Aug 26-28, Ft Lauderdale, FL&lt;br /&gt;
|http://www.accessdata.com/common/pagedetail.aspx?PageCode=train&lt;br /&gt;
|-&lt;br /&gt;
|AccessData&amp;amp;reg; BootCamp&lt;br /&gt;
|Sep 02-04, London, United Kingdom&lt;br /&gt;
|http://www.accessdata.com/common/pagedetail.aspx?PageCode=train&lt;br /&gt;
|-&lt;br /&gt;
|Seized Computer Evidence Recovery Specialist (SCERS)&lt;br /&gt;
|Sep 08-19, Glynco, GA&lt;br /&gt;
|http://www.fletc.gov/training/programs/computer-financial-investigations/technology-investigation&lt;br /&gt;
|Limited to Law Enforcement&lt;br /&gt;
|-&lt;br /&gt;
|Computer Hacking Forensic Investigator CHFI Prep/QFE Qualified Forensics Expert&lt;br /&gt;
|Sep 08-12, Reston, VA&lt;br /&gt;
|http://www.securityuniversity.net/classes_CHFI_QFE.php&lt;br /&gt;
|-&lt;br /&gt;
|BlackBag Introductory MacIntosh Forensics&lt;br /&gt;
|Sep 08-12, Washington D.C.&lt;br /&gt;
|http://www.blackbagtech.com/products/training.htm	&lt;br /&gt;
|-&lt;br /&gt;
|Macintosh Forensic Survival Course (MFSC) &lt;br /&gt;
|Sep 08-12, Bellingham, WA&lt;br /&gt;
|http://www.forwarddiscovery.com/shop/index.php?act=viewCat&amp;amp;catId=3&lt;br /&gt;
|-&lt;br /&gt;
|Windows NT File System(NTFS)&lt;br /&gt;
|Sep 08-11, St. Louis, MO&lt;br /&gt;
|http://www.nw3c.org/ocr/courses_desc.cfm&lt;br /&gt;
|Limited to Law Enforcement&lt;br /&gt;
|-&lt;br /&gt;
|Fundamentals of Computer Forensics Imaging&lt;br /&gt;
|Sep 9-12, Falls Church, VA&lt;br /&gt;
|http://www.mantech.com/msma/isso.asp&lt;br /&gt;
|-&lt;br /&gt;
|WetStone- Steganography Investigator Training&lt;br /&gt;
|Sep 10-11, Online &lt;br /&gt;
|https://www.wetstonetech.com/trainings.html&lt;br /&gt;
|-&lt;br /&gt;
|ILook® Automated Forensic Application(ILook)&lt;br /&gt;
|Sep 15-19, Meriden, CT&lt;br /&gt;
|http://www.nw3c.org/ocr/courses_desc.cfm&lt;br /&gt;
|Limited to Law Enforcement&lt;br /&gt;
|-&lt;br /&gt;
|WetStone- Hacking BootCamp for Investigators&lt;br /&gt;
|Sep 16-19, Charleston, SC&lt;br /&gt;
|https://www.wetstonetech.com/trainings.html&lt;br /&gt;
|-&lt;br /&gt;
|EnCase&amp;amp;reg; v6 Computer Forensics II&lt;br /&gt;
|Sep 16-19, Toronto, Canada&lt;br /&gt;
|http://www.guidancesoftware.com/training/course_schedule.aspx&lt;br /&gt;
|-&lt;br /&gt;
|AccessData&amp;amp;reg; Windows Forensics&lt;br /&gt;
|Sep 16-18, Columbia, SC&lt;br /&gt;
|http://www.accessdata.com/common/pagedetail.aspx?PageCode=train&lt;br /&gt;
|-&lt;br /&gt;
|BlackBag Intermediate MacIntosh Forensics&lt;br /&gt;
|Sep 22-26, Richmond, VA&lt;br /&gt;
|http://www.blackbagtech.com/products/training.htm&lt;br /&gt;
|Limited to Law Enforcement&lt;br /&gt;
|-&lt;br /&gt;
|EnCase&amp;amp;reg; v6 Advanced Computer Forensics&lt;br /&gt;
|Sep 23-26, Toronto, Canada&lt;br /&gt;
|http://www.guidancesoftware.com/training/course_schedule.aspx&lt;br /&gt;
|-&lt;br /&gt;
|AccessData&amp;amp;reg; Windows Forensics&lt;br /&gt;
|Sep 23-25, London, United Kingdom&lt;br /&gt;
|http://www.accessdata.com/common/pagedetail.aspx?PageCode=train&lt;br /&gt;
|-&lt;br /&gt;
|AccessData&amp;amp;reg; BootCamp&lt;br /&gt;
|Sep 23-25, Dallas, TX&lt;br /&gt;
|http://www.accessdata.com/common/pagedetail.aspx?PageCode=train&lt;br /&gt;
|-&lt;br /&gt;
|AccessData&amp;amp;reg; Applied Decryption&lt;br /&gt;
|Sep 23-25, Ft Lauderdale, FL and London, United Kingdom&lt;br /&gt;
|http://guest.cvent.com/EVENTS/Info/Summary.aspx?e=ab0c756b-3cf8-4161-8a70-0c11c6f018fc&lt;br /&gt;
|-&lt;br /&gt;
|X-Ways Forensics&lt;br /&gt;
|Sep 24-26, Alexandria, VA&lt;br /&gt;
|http://www.x-ways.net/training/washington_dc.html&lt;br /&gt;
|-&lt;br /&gt;
|BlackBag Introductory MacIntosh Forensics&lt;br /&gt;
|Sep 29-Oct 3, San Jose, CA&lt;br /&gt;
|http://www.blackbagtech.com/products/training.htm&lt;br /&gt;
|-&lt;br /&gt;
|X-Ways Forensics&lt;br /&gt;
|Sep 29-Oct 1, New York City, NY&lt;br /&gt;
|http://www.x-ways.net/training/new_york.html&lt;br /&gt;
|-&lt;br /&gt;
|WetStone- Live Investigator Training&lt;br /&gt;
|Sep 30- Oct 1, Fairfax, VA&lt;br /&gt;
|https://www.wetstonetech.com/trainings.html&lt;br /&gt;
|-&lt;br /&gt;
|EnCase&amp;amp;reg; v6 Computer Forensics II&lt;br /&gt;
|Sep 30-Oct 03, Toronto, Canada&lt;br /&gt;
|http://www.guidancesoftware.com/training/course_schedule.aspx&lt;br /&gt;
|-&lt;br /&gt;
|BlackBag Introductory MacIntosh Forensics&lt;br /&gt;
|Oct 06-10, Los Angeles, CA&lt;br /&gt;
|http://www.blackbagtech.com/products/training.htm&lt;br /&gt;
|-&lt;br /&gt;
|X-Ways Forensics&lt;br /&gt;
|Oct 07-09, London, UK&lt;br /&gt;
|http://www.x-ways.net/training/london.html&lt;br /&gt;
|-&lt;br /&gt;
|AccessData&amp;amp;reg; Windows Forensics&lt;br /&gt;
|Oct 07-09, Las Vegas, NV and New York City, NY&lt;br /&gt;
|http://www.accessdata.com/common/pagedetail.aspx?PageCode=train&lt;br /&gt;
|-&lt;br /&gt;
|WetStone- Steganography Investigator Training&lt;br /&gt;
|Oct 13-14, The Netherlands ENFSC Conference&lt;br /&gt;
|https://www.wetstonetech.com/trainings.html&lt;br /&gt;
|-&lt;br /&gt;
|AccessData&amp;amp;reg; BootCamp&lt;br /&gt;
|Oct 14-16, Louisville, KY&lt;br /&gt;
|http://www.accessdata.com/common/pagedetail.aspx?PageCode=train&lt;br /&gt;
|Limited to Law Enforcement&lt;br /&gt;
|-&lt;br /&gt;
|WetStone- Live Investigator Training&lt;br /&gt;
|Oct 18-19, Atlantic City, NJ HTCIA Conference&lt;br /&gt;
|https://www.wetstonetech.com/trainings.html&lt;br /&gt;
|-&lt;br /&gt;
|Computer Hacking Forensic Investigator CHFI Prep/QFE Qualified Forensics Expert&lt;br /&gt;
|Oct 20-24, Reston, VA&lt;br /&gt;
|http://www.securityuniversity.net/classes_CHFI_QFE.php&lt;br /&gt;
|-&lt;br /&gt;
|Windows NT Operating System(NTOS)&lt;br /&gt;
|Oct 20-23, St. Louis, MO&lt;br /&gt;
|http://www.nw3c.org/ocr/courses_desc.cfm&lt;br /&gt;
|Limited to Law Enforcement&lt;br /&gt;
|-&lt;br /&gt;
|EnCase&amp;amp;reg; v6 Computer Forensics II&lt;br /&gt;
|Oct 21-24, Toronto, Canada&lt;br /&gt;
|http://www.guidancesoftware.com/training/course_schedule.aspx&lt;br /&gt;
|-&lt;br /&gt;
|AccessData&amp;amp;reg; Applied Decryption&lt;br /&gt;
|Oct 23-25, Sterling, VA&lt;br /&gt;
|http://guest.cvent.com/EVENTS/Info/Summary.aspx?e=ab0c756b-3cf8-4161-8a70-0c11c6f018fc&lt;br /&gt;
|-&lt;br /&gt;
|Certified Steganography Examiner™&lt;br /&gt;
|Oct 23-24, Gaithersburg, MD&lt;br /&gt;
|http://www.sarc-wv.com/training/training_gaithersburg.aspx&lt;br /&gt;
|-&lt;br /&gt;
|WetStone- Live Investigator Training&lt;br /&gt;
|Oct 24-25, Gaithersburg, MD Techno Forensics Conference&lt;br /&gt;
|https://www.wetstonetech.com/trainings.html&lt;br /&gt;
|-&lt;br /&gt;
|WetStone- Steganography Investigator Training&lt;br /&gt;
|Oct 24-25, Gaithersburg, MD Techno Forensics Conference&lt;br /&gt;
|https://www.wetstonetech.com/trainings.html&lt;br /&gt;
|-&lt;br /&gt;
|X-Ways Forensics (3 days), File Systems Revealed (2 days)&lt;br /&gt;
|Oct 27-31, Canberra, Australia&lt;br /&gt;
|http://www.x-ways.net/training/&lt;br /&gt;
|Limited to Law Enforcement/Government&lt;br /&gt;
|-&lt;br /&gt;
|EnCase&amp;amp;reg; v6 EnScript&amp;amp;reg;  Programming - Phase I&lt;br /&gt;
|Oct 28-31, Toronto, Canada&lt;br /&gt;
|http://www.guidancesoftware.com/training/course_schedule.aspx&lt;br /&gt;
|-&lt;br /&gt;
|AccessData&amp;amp;reg; Windows Forensics&lt;br /&gt;
|Oct 28-30, Manchester, United Kingdom&lt;br /&gt;
|http://www.accessdata.com/common/pagedetail.aspx?PageCode=train&lt;br /&gt;
|-&lt;br /&gt;
|X-Ways Forensics&lt;br /&gt;
|Nov 03-05, Sydney, Australia&lt;br /&gt;
|http://www.x-ways.net/training/sydney.html&lt;br /&gt;
|-&lt;br /&gt;
|Macintosh Forensic Survival Course (MFSC) &lt;br /&gt;
|Nov 03-07, Bern, Switzerland&lt;br /&gt;
|http://www.forwarddiscovery.com/shop/index.php?act=viewCat&amp;amp;catId=3&lt;br /&gt;
|-&lt;br /&gt;
|Windows NT File System(NTFS)&lt;br /&gt;
|Nov 03-06, Meriden, CT&lt;br /&gt;
|http://www.nw3c.org/ocr/courses_desc.cfm&lt;br /&gt;
|Limited to Law Enforcement&lt;br /&gt;
|-&lt;br /&gt;
|EnCase&amp;amp;reg; v6 Computer Forensics II&lt;br /&gt;
|Nov 04-07, Toronto, Canada&lt;br /&gt;
|http://www.guidancesoftware.com/training/course_schedule.aspx&lt;br /&gt;
|-&lt;br /&gt;
|AccessData&amp;amp;reg; BootCamp&lt;br /&gt;
|Nov 04-06, London, United Kingdom&lt;br /&gt;
|http://www.accessdata.com/common/pagedetail.aspx?PageCode=train&lt;br /&gt;
|-&lt;br /&gt;
|AccessData&amp;amp;reg; Internet Forensics&lt;br /&gt;
|Nov 04-06, St Paul, MN&lt;br /&gt;
|http://www.accessdata.com/common/pagedetail.aspx?PageCode=train&lt;br /&gt;
|-&lt;br /&gt;
|AccessData&amp;amp;reg; Windows Forensics&lt;br /&gt;
|Nov 04-06, Albany, NY&lt;br /&gt;
|http://www.accessdata.com/common/pagedetail.aspx?PageCode=train&lt;br /&gt;
|-&lt;br /&gt;
|X-Ways Forensics&lt;br /&gt;
|Nov 11-13, Hong Kong&lt;br /&gt;
|http://www.x-ways.net/training/hong_kong.html&lt;br /&gt;
|-&lt;br /&gt;
|WetStone- Steganography Investigator Training&lt;br /&gt;
|Nov 11-12, Fairfax, VA&lt;br /&gt;
|https://www.wetstonetech.com/trainings.html&lt;br /&gt;
|-&lt;br /&gt;
|BlackBag Intermediate MacIntosh Forensics&lt;br /&gt;
|Nov 17-21, Washington D.C.&lt;br /&gt;
|http://www.blackbagtech.com/products/training.htm&lt;br /&gt;
|-&lt;br /&gt;
|WetStone- Hacking BootCamp for Investigators&lt;br /&gt;
|Nov 18-21, Vancouver BC&lt;br /&gt;
|https://www.wetstonetech.com/trainings.html&lt;br /&gt;
|-&lt;br /&gt;
|EnCase&amp;amp;reg; v6 Network Intrusion Investigations - Phase I&lt;br /&gt;
|Nov 18-21, Toronto, Canada&lt;br /&gt;
|http://www.guidancesoftware.com/training/course_schedule.aspx&lt;br /&gt;
|-&lt;br /&gt;
|EnCase&amp;amp;reg; v6 Computer Forensics II&lt;br /&gt;
|Nov 25-28, Toronto, Canada&lt;br /&gt;
|http://www.guidancesoftware.com/training/course_schedule.aspx&lt;br /&gt;
|-&lt;br /&gt;
|AccessData&amp;amp;reg; Internet Forensics&lt;br /&gt;
|Nov 25-27, Manchester, United Kingdom&lt;br /&gt;
|http://www.accessdata.com/common/pagedetail.aspx?PageCode=train&lt;br /&gt;
|-&lt;br /&gt;
|BlackBag Intermediate MacIntosh Forensics&lt;br /&gt;
|Dec 01-05, San Diego, CA&lt;br /&gt;
|http://www.blackbagtech.com/products/training.htm&lt;br /&gt;
|-&lt;br /&gt;
|Windows Internet Trace Evidence(INET)&lt;br /&gt;
|Dec 01-05, St. Louis, MO&lt;br /&gt;
|http://www.nw3c.org/ocr/courses_desc.cfm&lt;br /&gt;
|Limited to Law Enforcement&lt;br /&gt;
|-&lt;br /&gt;
|AccessData&amp;amp;reg; Windows Forensics&lt;br /&gt;
|Dec 02-04, Ft Lauderdale, FL; New York City, NY; and London, United Kingdom&lt;br /&gt;
|http://www.accessdata.com/common/pagedetail.aspx?PageCode=train&lt;br /&gt;
|-&lt;br /&gt;
|Fundamentals of Computer Forensics Imaging&lt;br /&gt;
|Dec 02-05, Falls Church, VA&lt;br /&gt;
|http://www.mantech.com/msma/isso.asp&lt;br /&gt;
|-&lt;br /&gt;
|Computer Hacking Forensic Investigator CHFI Prep/QFE Qualified Forensics Expert&lt;br /&gt;
|Dec 08-12, Reston, VA&lt;br /&gt;
|http://www.securityuniversity.net/classes_CHFI_QFE.php&lt;br /&gt;
|-&lt;br /&gt;
|Windows NT Operating System(NTOS)&lt;br /&gt;
|Dec 08-11, Meriden, CT&lt;br /&gt;
|http://www.nw3c.org/ocr/courses_desc.cfm&lt;br /&gt;
|Limited to Law Enforcement&lt;br /&gt;
|-&lt;br /&gt;
|Application Forensics Course&lt;br /&gt;
|Dec 08-19, Hong Kong Police College&lt;br /&gt;
|http://www.police.gov.hk/police/policecollege/english/pdl/pold.htm&lt;br /&gt;
|Limited to Law Enforcement&lt;br /&gt;
|-&lt;br /&gt;
|EnCase&amp;amp;reg; v6 Computer Forensics II&lt;br /&gt;
|Dec 09-12, Toronto, Canada&lt;br /&gt;
|http://www.guidancesoftware.com/training/course_schedule.aspx&lt;br /&gt;
|-&lt;br /&gt;
|AccessData&amp;amp;reg; Internet Forensics&lt;br /&gt;
|Dec 09-11, Dallas, TX and New York City, NY&lt;br /&gt;
|http://www.accessdata.com/common/pagedetail.aspx?PageCode=train&lt;br /&gt;
|-&lt;br /&gt;
|AccessData&amp;amp;reg; Windows Forensics&lt;br /&gt;
|Dec 09-11, Louisville, KY&lt;br /&gt;
|http://www.accessdata.com/common/pagedetail.aspx?PageCode=train&lt;br /&gt;
|Limited to Law Enforcement&lt;br /&gt;
|-&lt;br /&gt;
|EnCase&amp;amp;reg; v6 Advanced Computer Forensics&lt;br /&gt;
|Dec 16-19, Toronto, Canada&lt;br /&gt;
|http://www.guidancesoftware.com/training/course_schedule.aspx&lt;br /&gt;
|-&lt;br /&gt;
|AccessData&amp;amp;reg; BootCamp&lt;br /&gt;
|Dec 16-18, Manchester, United Kingdom&lt;br /&gt;
|http://www.accessdata.com/common/pagedetail.aspx?PageCode=train&lt;br /&gt;
|-&lt;br /&gt;
|**__2009 EVENTS__**&lt;br /&gt;
|_______2009_______&lt;br /&gt;
|-&lt;br /&gt;
|Linux File System for Computer Forensic Examiners(Linux)&lt;br /&gt;
|Jan 12-16, 2009, St. Louis, MO&lt;br /&gt;
|http://www.nw3c.org/ocr/courses_desc.cfm&lt;br /&gt;
|Limited to Law Enforcement&lt;br /&gt;
|-&lt;br /&gt;
|Windows Internet Trace Evidence(INET)&lt;br /&gt;
|Jan 19-23, 2009, Meriden, CT&lt;br /&gt;
|http://www.nw3c.org/ocr/courses_desc.cfm&lt;br /&gt;
|Limited to Law Enforcement&lt;br /&gt;
|-&lt;br /&gt;
|Linux File System for Computer Forensic Examiners(Linux)&lt;br /&gt;
|Mar 02-06, 2009, Meriden, CT&lt;br /&gt;
|http://www.nw3c.org/ocr/courses_desc.cfm&lt;br /&gt;
|Limited to Law Enforcement&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Pmow</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Talk:Reiserfs</id>
		<title>Talk:Reiserfs</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Talk:Reiserfs"/>
				<updated>2008-07-17T20:17:26Z</updated>
		
		<summary type="html">&lt;p&gt;Pmow: New page: &amp;lt;pre&amp;gt;Reporting-MTA: dns;bigfish.com Received-From-MTA: dns;mail12-va3-R.bigfish.com Arrival-Date: Thu, 17 Jul 2008 15:33:29 +0000  Final-Recipient: rfc822;florian@purdue.edu Action: failed...&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;pre&amp;gt;Reporting-MTA: dns;bigfish.com&lt;br /&gt;
Received-From-MTA: dns;mail12-va3-R.bigfish.com&lt;br /&gt;
Arrival-Date: Thu, 17 Jul 2008 15:33:29 +0000&lt;br /&gt;
&lt;br /&gt;
Final-Recipient: rfc822;florian@purdue.edu&lt;br /&gt;
Action: failed&lt;br /&gt;
Status: 5.1.1&lt;br /&gt;
Diagnostic-Code: smtp;550 5.1.1 &amp;lt;florian@purdue.edu&amp;gt;... User unknown&lt;br /&gt;
Remote-MTA: dns;mailhub248.itcs.purdue.edu&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
I got the above when attempting to contact &amp;quot;Florian&amp;quot; for copyright information...the page was last modified Jan 26th 2006 and I might've not cited the page correctly at all here.&lt;/div&gt;</summary>
		<author><name>Pmow</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/AccessData</id>
		<title>AccessData</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/AccessData"/>
				<updated>2008-07-17T20:11:43Z</updated>
		
		<summary type="html">&lt;p&gt;Pmow: Changed FTK tag to reflect official site, added Mobile Phone Examiner update&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;''AccessData'' offers computer forensics software and training. Their flagship product is [[Forensic Toolkit]], but they offer several others including:&lt;br /&gt;
* [[FTK Imager]]&lt;br /&gt;
* [[PRTK|Password Recovery Toolkit]], a workstation-level password cracking application.&lt;br /&gt;
* [[DNA|Distributed Network Attack]], their distributed cyptographic brute force cracking network.&lt;br /&gt;
* [[FTK Mobile Phone Examiner]], a cellular phone evidence collection tool.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Trivia ==&lt;br /&gt;
&lt;br /&gt;
In 2006, a team from AccessData won the [[DC3 Digital Forensics Challenge]]. &lt;br /&gt;
&lt;br /&gt;
== External Links == &lt;br /&gt;
&lt;br /&gt;
[http://www.accessdata.com/ Official Website]&lt;br /&gt;
&lt;br /&gt;
[[Category:Vendor]]&lt;/div&gt;</summary>
		<author><name>Pmow</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/File:Superblock_example.png</id>
		<title>File:Superblock example.png</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/File:Superblock_example.png"/>
				<updated>2008-07-17T18:27:32Z</updated>
		
		<summary type="html">&lt;p&gt;Pmow: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Pmow</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Reiserfs</id>
		<title>Reiserfs</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Reiserfs"/>
				<updated>2008-07-17T18:27:24Z</updated>
		
		<summary type="html">&lt;p&gt;Pmow: Editing GIFs to PNG since GIFs are not allowed&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Detecting ReiserFS in a forensics environment ==&lt;br /&gt;
&lt;br /&gt;
[[Image:Superblock.png]]&lt;br /&gt;
&lt;br /&gt;
Note: These are in [http://en.wikipedia.org/wiki/Little_endian little-endian] format. [[User:Pmow|Pmow]] 18:21, 17 July 2008 (UTC)&lt;br /&gt;
&amp;lt;table border=&amp;quot;0&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;th&amp;gt; '''Name''' &amp;lt;/th&amp;gt;&lt;br /&gt;
&lt;br /&gt;
        &amp;lt;th&amp;gt; Size &amp;lt;/th&amp;gt;&lt;br /&gt;
        &amp;lt;th&amp;gt; Description &amp;lt;/th&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Block count &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  4 &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
        &amp;lt;td&amp;gt;  The number of blocks in the partition &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Free blocks &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  4 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  The number of free blocks in the partition &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Root block &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  4 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  The block number of the block containing the root node &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Journal block &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  4 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  The block number of the block containing the first journal node &amp;lt;!--&amp;lt;/tr--&amp;gt;&lt;br /&gt;
&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Journal device &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  4 &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
        &amp;lt;td&amp;gt;  Journal device number (not sure what for) &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Orig. journal size &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  4 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  Original journal size. Needed when using partition on systems with different default journal sizes.&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Journal trans. max &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  4 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  The maximum number of blocks in a transaction &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Journal magic &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  4 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  A random magic number &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Journal max batch &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  4 &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
        &amp;lt;td&amp;gt;  The maximum number of blocks in a transaction &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Journal max commit age &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  4 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  Time in seconds of how old an asynchronous commit can be &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Journal max trans. age &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  4 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  Time in seconds of how old a transaction can be &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Blocksize &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  2 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  The size in bytes of a block &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; OID max size &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  2 &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
        &amp;lt;td&amp;gt;  The maximum size of the object id array &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; OID current size &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  2 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  The current size of the object id array &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; State &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  2 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  State of the partition: valid (1) or error (2) &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Magic string &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  12 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  The reiserfs magic string, should be &amp;quot;ReIsEr2Fs&amp;quot; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Hash function code &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  4 &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
        &amp;lt;td&amp;gt;  The  hash function that is being used to sort names in a directory&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Tree Height &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  2 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  The current height of the disk tree &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Bitmap number &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  2 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  The amount of bitmap blocks needed to address each block of the file system&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Version &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  2 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  The reiserfs version number &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Reserved &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  2 &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
        &amp;lt;td&amp;gt;  &amp;amp;nbsp; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Inode Generation &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  4 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  Number of the current inode generation. &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The following is the start of the superblock of a 256MB reiserfs partition on an Intel based system:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/p&amp;gt;&amp;lt;pre&amp;gt;00000000 66 00 01 00 93 18 00 00 82 40 00 00 12 00 00 00  f........@......&lt;br /&gt;
00000010 00 00 00 00 00 20 00 00 00 04 00 00 ac 34 11 57  ..... ......¬4.W&lt;br /&gt;
00000020 84 03 00 00 1e 00 00 00 00 00 00 00 00 10 cc 03  ..............Ì.&lt;br /&gt;
00000030 08 00 02 00 52 65 49 73 45 72 32 46 73 00 00 00  ....ReIsEr2Fs...&lt;br /&gt;
00000040 03 00 00 00 04 00 03 00 02 00 00 00 dc 52 00 00  ............ÜR..&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Image:superblock_example.png]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;Block count: 65638&lt;br /&gt;
&amp;lt;br&amp;gt;Free blocks: 6291&lt;br /&gt;
&amp;lt;br&amp;gt;Root block: 16514&lt;br /&gt;
&amp;lt;br&amp;gt;Journal block: 18&lt;br /&gt;
&amp;lt;br&amp;gt;Journal device: 0&lt;br /&gt;
&amp;lt;br&amp;gt;Original journal size: 8192&lt;br /&gt;
&amp;lt;br&amp;gt;Journal trans. max: 1024&lt;br /&gt;
&amp;lt;br&amp;gt;Journal magic: 1460745388&lt;br /&gt;
&amp;lt;br&amp;gt;Journal max. batch: 900&lt;br /&gt;
&amp;lt;br&amp;gt;Journal max. commit age: 30&lt;br /&gt;
&amp;lt;br&amp;gt;Journal max. trans. age: 0&lt;br /&gt;
&amp;lt;br&amp;gt;Blocksize: 4096&lt;br /&gt;
&amp;lt;br&amp;gt;OID max. size: 972&lt;br /&gt;
&amp;lt;br&amp;gt;OID current size: 8&lt;br /&gt;
&amp;lt;br&amp;gt;State: 2 (error)&lt;br /&gt;
&amp;lt;br&amp;gt;Magic String: ReIsEr2Fs&lt;br /&gt;
&amp;lt;br&amp;gt;Hash function code: 3&lt;br /&gt;
&amp;lt;br&amp;gt;Tree height: 4&lt;br /&gt;
&amp;lt;br&amp;gt;Bitmap number: 3&lt;br /&gt;
&amp;lt;br&amp;gt;Version: 2&lt;br /&gt;
&amp;lt;br&amp;gt;Inode generation: 21212&lt;br /&gt;
&lt;br /&gt;
== External Links ==&lt;br /&gt;
* [http://en.wikipedia.org/wiki/Reiserfs ReiserFS on Wikipedia]&lt;br /&gt;
* [http://homes.cerias.purdue.edu/~florian/reiser/reiserfs.php The structure of the Reiser file system]&lt;/div&gt;</summary>
		<author><name>Pmow</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Reiserfs</id>
		<title>Reiserfs</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Reiserfs"/>
				<updated>2008-07-17T18:26:42Z</updated>
		
		<summary type="html">&lt;p&gt;Pmow: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Detecting ReiserFS in a forensics environment ==&lt;br /&gt;
&lt;br /&gt;
[[Image:Superblock.png]]&lt;br /&gt;
&lt;br /&gt;
Note: These are in [http://en.wikipedia.org/wiki/Little_endian little-endian] format. [[User:Pmow|Pmow]] 18:21, 17 July 2008 (UTC)&lt;br /&gt;
&amp;lt;table border=&amp;quot;0&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;th&amp;gt; '''Name''' &amp;lt;/th&amp;gt;&lt;br /&gt;
&lt;br /&gt;
        &amp;lt;th&amp;gt; Size &amp;lt;/th&amp;gt;&lt;br /&gt;
        &amp;lt;th&amp;gt; Description &amp;lt;/th&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Block count &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  4 &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
        &amp;lt;td&amp;gt;  The number of blocks in the partition &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Free blocks &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  4 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  The number of free blocks in the partition &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Root block &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  4 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  The block number of the block containing the root node &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Journal block &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  4 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  The block number of the block containing the first journal node &amp;lt;!--&amp;lt;/tr--&amp;gt;&lt;br /&gt;
&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Journal device &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  4 &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
        &amp;lt;td&amp;gt;  Journal device number (not sure what for) &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Orig. journal size &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  4 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  Original journal size. Needed when using partition on systems with different default journal sizes.&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Journal trans. max &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  4 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  The maximum number of blocks in a transaction &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Journal magic &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  4 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  A random magic number &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Journal max batch &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  4 &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
        &amp;lt;td&amp;gt;  The maximum number of blocks in a transaction &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Journal max commit age &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  4 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  Time in seconds of how old an asynchronous commit can be &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Journal max trans. age &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  4 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  Time in seconds of how old a transaction can be &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Blocksize &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  2 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  The size in bytes of a block &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; OID max size &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  2 &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
        &amp;lt;td&amp;gt;  The maximum size of the object id array &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; OID current size &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  2 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  The current size of the object id array &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; State &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  2 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  State of the partition: valid (1) or error (2) &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Magic string &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  12 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  The reiserfs magic string, should be &amp;quot;ReIsEr2Fs&amp;quot; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Hash function code &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  4 &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
        &amp;lt;td&amp;gt;  The  hash function that is being used to sort names in a directory&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Tree Height &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  2 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  The current height of the disk tree &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Bitmap number &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  2 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  The amount of bitmap blocks needed to address each block of the file system&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Version &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  2 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  The reiserfs version number &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Reserved &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  2 &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
        &amp;lt;td&amp;gt;  &amp;amp;nbsp; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Inode Generation &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  4 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  Number of the current inode generation. &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The following is the start of the superblock of a 256MB reiserfs partition on an Intel based system:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/p&amp;gt;&amp;lt;pre&amp;gt;00000000 66 00 01 00 93 18 00 00 82 40 00 00 12 00 00 00  f........@......&lt;br /&gt;
00000010 00 00 00 00 00 20 00 00 00 04 00 00 ac 34 11 57  ..... ......¬4.W&lt;br /&gt;
00000020 84 03 00 00 1e 00 00 00 00 00 00 00 00 10 cc 03  ..............Ì.&lt;br /&gt;
00000030 08 00 02 00 52 65 49 73 45 72 32 46 73 00 00 00  ....ReIsEr2Fs...&lt;br /&gt;
00000040 03 00 00 00 04 00 03 00 02 00 00 00 dc 52 00 00  ............ÜR..&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Image:superblock_example.gif]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;Block count: 65638&lt;br /&gt;
&amp;lt;br&amp;gt;Free blocks: 6291&lt;br /&gt;
&amp;lt;br&amp;gt;Root block: 16514&lt;br /&gt;
&amp;lt;br&amp;gt;Journal block: 18&lt;br /&gt;
&amp;lt;br&amp;gt;Journal device: 0&lt;br /&gt;
&amp;lt;br&amp;gt;Original journal size: 8192&lt;br /&gt;
&amp;lt;br&amp;gt;Journal trans. max: 1024&lt;br /&gt;
&amp;lt;br&amp;gt;Journal magic: 1460745388&lt;br /&gt;
&amp;lt;br&amp;gt;Journal max. batch: 900&lt;br /&gt;
&amp;lt;br&amp;gt;Journal max. commit age: 30&lt;br /&gt;
&amp;lt;br&amp;gt;Journal max. trans. age: 0&lt;br /&gt;
&amp;lt;br&amp;gt;Blocksize: 4096&lt;br /&gt;
&amp;lt;br&amp;gt;OID max. size: 972&lt;br /&gt;
&amp;lt;br&amp;gt;OID current size: 8&lt;br /&gt;
&amp;lt;br&amp;gt;State: 2 (error)&lt;br /&gt;
&amp;lt;br&amp;gt;Magic String: ReIsEr2Fs&lt;br /&gt;
&amp;lt;br&amp;gt;Hash function code: 3&lt;br /&gt;
&amp;lt;br&amp;gt;Tree height: 4&lt;br /&gt;
&amp;lt;br&amp;gt;Bitmap number: 3&lt;br /&gt;
&amp;lt;br&amp;gt;Version: 2&lt;br /&gt;
&amp;lt;br&amp;gt;Inode generation: 21212&lt;br /&gt;
&lt;br /&gt;
== External Links ==&lt;br /&gt;
* [http://en.wikipedia.org/wiki/Reiserfs ReiserFS on Wikipedia]&lt;br /&gt;
* [http://homes.cerias.purdue.edu/~florian/reiser/reiserfs.php The structure of the Reiser file system]&lt;/div&gt;</summary>
		<author><name>Pmow</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/File:Superblock.png</id>
		<title>File:Superblock.png</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/File:Superblock.png"/>
				<updated>2008-07-17T18:26:19Z</updated>
		
		<summary type="html">&lt;p&gt;Pmow: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Pmow</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Reiserfs</id>
		<title>Reiserfs</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Reiserfs"/>
				<updated>2008-07-17T18:21:07Z</updated>
		
		<summary type="html">&lt;p&gt;Pmow: Creation, not attributed yet&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Detecting ReiserFS in a forensics environment ==&lt;br /&gt;
&lt;br /&gt;
[[Image:Superblock.gif]]&lt;br /&gt;
&lt;br /&gt;
Note: These are in [http://en.wikipedia.org/wiki/Little_endian little-endian] format. [[User:Pmow|Pmow]] 18:21, 17 July 2008 (UTC)&lt;br /&gt;
&amp;lt;table border=&amp;quot;0&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;th&amp;gt; '''Name''' &amp;lt;/th&amp;gt;&lt;br /&gt;
&lt;br /&gt;
        &amp;lt;th&amp;gt; Size &amp;lt;/th&amp;gt;&lt;br /&gt;
        &amp;lt;th&amp;gt; Description &amp;lt;/th&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Block count &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  4 &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
        &amp;lt;td&amp;gt;  The number of blocks in the partition &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Free blocks &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  4 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  The number of free blocks in the partition &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Root block &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  4 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  The block number of the block containing the root node &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Journal block &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  4 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  The block number of the block containing the first journal node &amp;lt;!--&amp;lt;/tr--&amp;gt;&lt;br /&gt;
&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Journal device &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  4 &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
        &amp;lt;td&amp;gt;  Journal device number (not sure what for) &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Orig. journal size &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  4 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  Original journal size. Needed when using partition on systems with different default journal sizes.&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Journal trans. max &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  4 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  The maximum number of blocks in a transaction &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Journal magic &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  4 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  A random magic number &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Journal max batch &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  4 &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
        &amp;lt;td&amp;gt;  The maximum number of blocks in a transaction &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Journal max commit age &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  4 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  Time in seconds of how old an asynchronous commit can be &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Journal max trans. age &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  4 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  Time in seconds of how old a transaction can be &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Blocksize &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  2 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  The size in bytes of a block &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; OID max size &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  2 &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
        &amp;lt;td&amp;gt;  The maximum size of the object id array &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; OID current size &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  2 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  The current size of the object id array &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; State &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  2 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  State of the partition: valid (1) or error (2) &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Magic string &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  12 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  The reiserfs magic string, should be &amp;quot;ReIsEr2Fs&amp;quot; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Hash function code &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  4 &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
        &amp;lt;td&amp;gt;  The  hash function that is being used to sort names in a directory&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Tree Height &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  2 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  The current height of the disk tree &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Bitmap number &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  2 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  The amount of bitmap blocks needed to address each block of the file system&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Version &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  2 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  The reiserfs version number &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Reserved &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  2 &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
        &amp;lt;td&amp;gt;  &amp;amp;nbsp; &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt; Inode Generation &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td align=&amp;quot;center&amp;quot;&amp;gt;  4 &amp;lt;/td&amp;gt;&lt;br /&gt;
        &amp;lt;td&amp;gt;  Number of the current inode generation. &amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The following is the start of the superblock of a 256MB reiserfs partition on an Intel based system:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/p&amp;gt;&amp;lt;pre&amp;gt;00000000 66 00 01 00 93 18 00 00 82 40 00 00 12 00 00 00  f........@......&lt;br /&gt;
00000010 00 00 00 00 00 20 00 00 00 04 00 00 ac 34 11 57  ..... ......¬4.W&lt;br /&gt;
00000020 84 03 00 00 1e 00 00 00 00 00 00 00 00 10 cc 03  ..............Ì.&lt;br /&gt;
00000030 08 00 02 00 52 65 49 73 45 72 32 46 73 00 00 00  ....ReIsEr2Fs...&lt;br /&gt;
00000040 03 00 00 00 04 00 03 00 02 00 00 00 dc 52 00 00  ............ÜR..&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Image:superblock_example.gif]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;Block count: 65638&lt;br /&gt;
&amp;lt;br&amp;gt;Free blocks: 6291&lt;br /&gt;
&amp;lt;br&amp;gt;Root block: 16514&lt;br /&gt;
&amp;lt;br&amp;gt;Journal block: 18&lt;br /&gt;
&amp;lt;br&amp;gt;Journal device: 0&lt;br /&gt;
&amp;lt;br&amp;gt;Original journal size: 8192&lt;br /&gt;
&amp;lt;br&amp;gt;Journal trans. max: 1024&lt;br /&gt;
&amp;lt;br&amp;gt;Journal magic: 1460745388&lt;br /&gt;
&amp;lt;br&amp;gt;Journal max. batch: 900&lt;br /&gt;
&amp;lt;br&amp;gt;Journal max. commit age: 30&lt;br /&gt;
&amp;lt;br&amp;gt;Journal max. trans. age: 0&lt;br /&gt;
&amp;lt;br&amp;gt;Blocksize: 4096&lt;br /&gt;
&amp;lt;br&amp;gt;OID max. size: 972&lt;br /&gt;
&amp;lt;br&amp;gt;OID current size: 8&lt;br /&gt;
&amp;lt;br&amp;gt;State: 2 (error)&lt;br /&gt;
&amp;lt;br&amp;gt;Magic String: ReIsEr2Fs&lt;br /&gt;
&amp;lt;br&amp;gt;Hash function code: 3&lt;br /&gt;
&amp;lt;br&amp;gt;Tree height: 4&lt;br /&gt;
&amp;lt;br&amp;gt;Bitmap number: 3&lt;br /&gt;
&amp;lt;br&amp;gt;Version: 2&lt;br /&gt;
&amp;lt;br&amp;gt;Inode generation: 21212&lt;br /&gt;
&lt;br /&gt;
== External Links ==&lt;br /&gt;
* [http://en.wikipedia.org/wiki/Reiserfs ReiserFS on Wikipedia]&lt;br /&gt;
* [http://homes.cerias.purdue.edu/~florian/reiser/reiserfs.php The structure of the Reiser file system]&lt;/div&gt;</summary>
		<author><name>Pmow</name></author>	</entry>

	</feed>