Difference between pages "DCO and HPA" and "Libpff"

From ForensicsWiki
(Difference between pages)
Jump to: navigation, search
m (References)
 
 
Line 1: Line 1:
==Tools==
+
{{Infobox_Software |
* [http://www.vidstrom.net/stools/taft/ TAFT (The ATA Forensics Tool)] claims the ability to look at and change the HPA and DCO settings.
+
  name = libpff |
 +
  maintainer = [[Joachim Metz]] |
 +
  os = [[Linux]], [[FreeBSD]], [[NetBSD]], [[OpenBSD]], [[Mac OS X]], [[Windows]] |
 +
  genre = {{Analysis}} |
 +
  license = {{LGPL}} |
 +
  website = [http://libpff.sourceforge.net libpff.sourceforge.net] |
 +
}}
  
* [http://www.softpedia.com/get/Security/Security-Related/SAFE-Block.shtml SAFE-Block], claims the ability to temporarily remove the HPA and remove the DCO and later return it to its original state.
+
The '''libpff''' package contains [[Linux]] based library and applications to read [[Personal Folder Files (PAB, PST, OST)]] files.
  
==References==
+
It has been ported to other platforms like [[FreeBSD]] [[NetBSD]] [[OpenBSD]] [[Mac OS X]] and [[Windows]] as well.
* [http://www.sciencedirect.com/science?_ob=ArticleURL&_udi=B7CW4-4HR72JM-2&_user=3326500&_rdoc=1&_fmt=&_orig=search&_sort=d&view=c&_acct=C000060280&_version=1&_urlVersion=0&_userid=3326500&md5=030e6e2928779b385c76658736d11b98 Methods of discovery and exploitation of Host Protected Areas on IDE storage devices that conform to ATAPI-4], Mark Bedford, Digital Investigation, Volume 2, Issue 4, December 2005, Pages 268-275
+
  
* [http://www.utica.edu/academic/institutes/ecii/publications/articles/EFE36584-D13F-2962-67BEB146864A2671.pdf Hidden Disk Areas: HPA and DCO], Mayank R. Gupta, Michael D. Hoeschele, Marcus K. Rogers, International Journal of Digital Evidence, Fall 2006, Volume 5, Issue 1
+
== History ==
 +
 
 +
Libpff was created by [[Joachim Metz]] in 2008, while working for [http://en.hoffmannbv.nl/ Hoffmann Investigations].
 +
 
 +
Libpff is a rewrite of earlier work on the PST file format by the [http://www.five-ten-sg.com/libpst/ libpst project]. Libpff was updated to be a shared library and support the OST and PAB files.
 +
 
 +
Currently libpff partially supports the data in PAB files.
 +
 
 +
== Tools ==
 +
The '''libpff''' package contains the following tools:
 +
* '''pffexport''', which exports the items stored in PAB, PST and OST (PFF) files
 +
* '''pffinfo''', which shows information about PFF files.
 +
* '''pffrecover''', which exports recovered items stored in PAB, PST and OST (PFF) files
 +
 
 +
== External Links ==
 +
 
 +
* [http://libpff.sourceforge.net libpfff project site]

Revision as of 06:24, 31 January 2009

libpff
Maintainer: Joachim Metz
OS: Linux, FreeBSD, NetBSD, OpenBSD, Mac OS X, Windows
Genre: Analysis
License: LGPL
Website: libpff.sourceforge.net

The libpff package contains Linux based library and applications to read Personal Folder Files (PAB, PST, OST) files.

It has been ported to other platforms like FreeBSD NetBSD OpenBSD Mac OS X and Windows as well.

History

Libpff was created by Joachim Metz in 2008, while working for Hoffmann Investigations.

Libpff is a rewrite of earlier work on the PST file format by the libpst project. Libpff was updated to be a shared library and support the OST and PAB files.

Currently libpff partially supports the data in PAB files.

Tools

The libpff package contains the following tools:

  • pffexport, which exports the items stored in PAB, PST and OST (PFF) files
  • pffinfo, which shows information about PFF files.
  • pffrecover, which exports recovered items stored in PAB, PST and OST (PFF) files

External Links