Michael Lazin via plug on 25 Jun 2023 18:42:25 -0700


[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]

Re: [PLUG] makeshift forensic copy with scp


Thank you Steve.  It is actually an openwrt router so it would be challenging to make a copy with dd.  I am more interested in examining the rest of the filesystem because I can pull it from github and do a diff of the filesystem because I have made very few changes so this would work for me.  I found a rogue service in /etc/init.d on the router and I would ideally like to compare my router with a fresh pull from github.  Please excuse me but I am treating this like a Linux system because it is but it is separated from the outside with very strong firewall rules.  Thanks again.  

Michael Lazin

.. τὸ γὰρ αὐτὸ νοεῖν ἐστίν τε καὶ εἶναι.


On Sun, Jun 25, 2023 at 8:48 PM Steve Litt via plug <plug@lists.phillylinux.org> wrote:
Michael Lazin via plug said on Sun, 25 Jun 2023 19:54:40 -0400

>I have a system that I found malware on and I want to examine it
>locally. I connected to it with ssh as root,

The generally accepted way to make a forensic copy is to boot a
different OS, then dd the suspect hard disk to an image. Is there
anyone with hands-on at the current location of the suspect hard disk
who could do this?

Thanks,

SteveT

Steve Litt
Autumn 2022 featured book: Thriving in Tough Times
http://www.troubleshooters.com/bookstore/thrive.htm
___________________________________________________________________________
Philadelphia Linux Users Group         --        http://www.phillylinux.org
Announcements - http://lists.phillylinux.org/mailman/listinfo/plug-announce
General Discussion  --   http://lists.phillylinux.org/mailman/listinfo/plug
___________________________________________________________________________
Philadelphia Linux Users Group         --        http://www.phillylinux.org
Announcements - http://lists.phillylinux.org/mailman/listinfo/plug-announce
General Discussion  --   http://lists.phillylinux.org/mailman/listinfo/plug