Тёмный

RECOVERING FILES with Autopsy (PicoCTF 2022 #47 'operation-oni') 

John Hammond
Подписаться 1,8 млн
Просмотров 28 тыс.
50% 1

Опубликовано:

 

9 сен 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 43   
@BarYamin
@BarYamin 2 года назад
If you want to understand the rwx permission set, it's better to interpret it as binary. Basically, we have 3 bits that each represent r, w, and x, respectively. so, let's say I want read & execute, this translates to r-x, which translates in binary to 101, which then in turn converts to 4+1=5 in base10 :)
@MrToast72
@MrToast72 2 года назад
Briefly talks about Chmod three digit codes "you can look up resources on how this exactly works" then proceeds to explain how it exactly works lol thank you John, I love when you do that!
@TheNobleSavage612
@TheNobleSavage612 2 года назад
"i need to look for keys" hovers over the key folder and moves on
@rahimmahat0007
@rahimmahat0007 2 года назад
Exactly, I was like John you just passed right through it
@adinathrangnekar3064
@adinathrangnekar3064 Год назад
Same
@testentry353
@testentry353 2 года назад
one easy way to remember the file permissions is to know that read is 4, write is 2, and execute is 1 so r-x will be 4+1=5 and rw- will be 4+2=6
@ericbarlow6772
@ericbarlow6772 2 года назад
It’s binary. RWX is a bit either on (1) or off (0). Read only is 100 in binary or 0*2^0 + 0*2^1 + 1*2^2 = 4.
@abiolasamuel9760
@abiolasamuel9760 Год назад
Hello 👋 My samsung a71 phone was factory reset remotely and I don't have any backup whatsoever, is it possible to recover the phone data
@SESUAV
@SESUAV 2 года назад
I used binwalk too. It was quick and easy using that than autopsy because of command line
@wisemasterbuilder
@wisemasterbuilder 2 года назад
Love this Format Mighty Friend! You can lead a horse to water but ya can't always git'em to drink.
@fjr2go
@fjr2go 2 года назад
I like the 'short' informative videos like these. Thanks
@viv_2489
@viv_2489 2 года назад
Really like the alternate solution / additional extra curricular activity that you mention as applicable....
@maxxinev.pennelope7179
@maxxinev.pennelope7179 2 года назад
Watching this on the TV cast with my father fingers crossed 🤞 it's not to over my or rather our head(s).
@IAmCandal
@IAmCandal 2 года назад
HOLY SHIT BRO YOU DONT EVEN KNOW HOW HELPFUL THIS WAS FOR ME HOMIE
@eavi4645
@eavi4645 2 года назад
Great video, love the content. Thank you!
@Zerback
@Zerback 2 года назад
Great content John! Keep it up!
@jreamscape
@jreamscape 7 месяцев назад
thanks dude
@omaralhalboosi2713
@omaralhalboosi2713 2 года назад
Great great video John, but dude you are like sonic speed lol barely catching up , which made this vid a 40 minutes show. But the point is this is great . May God bless you brother
@zer001
@zer001 2 года назад
Nice one as allways!
@rationalbushcraft
@rationalbushcraft 2 года назад
I like using autopsy and we don't even do traditional forensics as my state requires you be a PI of all things to do that. But I do use it for data recovery and I even use a hardware write blocker. Probably seems like overkill but I never have to say that I may have changed something so if the end user wants to send it to Ontrack or some other place I can argue that we never changed anything.
@abiolasamuel9760
@abiolasamuel9760 Год назад
Hello 👋 My phone was factory reset remotely and I don't have any backup whatsoever, is it possible to recover my phone data
@debarghyamaitra
@debarghyamaitra 2 года назад
I did it with commands icat and fls....it was a lot hectic though!
@booruledie3052
@booruledie3052 2 года назад
cant wait for htb cyber apocalypse videos.
@Lacsap3366
@Lacsap3366 Год назад
Lol I just mounted the root partition as a loop device with losetup
@bech2342
@bech2342 2 года назад
uh, he saw for the first time a kernel source tree 🙊 binwalk FTW!
@yaserbasaad7984
@yaserbasaad7984 2 года назад
You are Epic
@hallgowrt
@hallgowrt 2 года назад
the audio seemed low at full volume was I able to hear anything as always great vid
@Youtupe69
@Youtupe69 2 года назад
Whats this GUI, I've used autopsy on windows and it wasnt a web app, had a much nicer GUI... Is it not available on Linux?
@kiyu3229
@kiyu3229 Год назад
It is you can install it with apt
@johnmcmanus6719
@johnmcmanus6719 2 года назад
The SSH key wasn't a deleted file though
@ecjb1969
@ecjb1969 2 года назад
Couldn’t you just midair image; mount -t iso9660 -o loop disk.img image to mount the disk image and then use find to look for SSH keys and the like?
@luthfisukma9787
@luthfisukma9787 2 года назад
are you use linux for daily driver ??
@CA-FE-C0-FF-EE-00
@CA-FE-C0-FF-EE-00 2 года назад
Watching this file failing the htb CTF xD only 8 challenges done, but I'm alone ^^
@johny_dope8575
@johny_dope8575 2 года назад
1
@guilherme5094
@guilherme5094 2 года назад
👍
@re70-december32
@re70-december32 2 года назад
Hiiiii
@msasdc2087
@msasdc2087 2 года назад
Finnaly, I got your home address.
@shocker9434
@shocker9434 2 года назад
13:40 whats that finish command 🤔🤔 can anyone explain?
@PR1NC3
@PR1NC3 2 года назад
he created bash script to rename the working folder with prifix _completed
@shocker9434
@shocker9434 2 года назад
@@PR1NC3 oh got it. thanks
@herrpez
@herrpez 2 года назад
I love your content, but calling things a "gimmick" when they're far from it... that's... grating. :(
@abiolasamuel9760
@abiolasamuel9760 Год назад
Hello 👋 My phone was factory reset remotely and I don't have any backup whatsoever, is it possible to recover my phone data
@abiolasamuel9760
@abiolasamuel9760 Год назад
Hello 👋 My phone was factory reset remotely and I don't have any backup whatsoever, is it possible to recover my phone data
Далее
Return Oriented Programming (PicoCTF 2022 #48 'ropfu')
35:09
Self-Extracting Executables for Hackers
41:06
Просмотров 36 тыс.
Notepad.exe Will Snitch On You (full coding project)
53:30
Linux Forensics with Linux - CTF Walkthrough
42:00
Просмотров 15 тыс.
Finding WEIRD Devices on the Public Internet
27:48
Просмотров 277 тыс.