July 31 2011

Application of Computer Forensics Using Data Recovery Technologies

Tagged Under : , , , , , , , , , , , , , , , , , , , , , , , , , ,

Article by MAKY

Introduction: With the sky-rocking increase of computer network crime rate, the advanced data recovery technology, computer forensics technology are widely used in this field. This article focuses on the two technologies development and applications, with introduction of the related advanced tools and the future treads.In recent years, the computer crime cases are soaring with characteristics of professional, intelligentized, complex and multiplex with sever bad result, which is apparently different from traditional crimes. As a result, the construction of this computer forensics technology is of significant meaning.With years’ development, the general and provincial police ministry are organizing a computer crime bureau specially for the current conditions. But the fact is that there needs much more efforts to be put in integration of this working stuff and technology and the organizations.I. Based on factory-level theory of data recovery and computer forensics technologies??With the popularization of computers and application of networks, all kinds of storage media have now been a vital irreplaceable part of people’s lives. Cases with the spread of eroticism, defraud money and property, blackmail and illegal pyramids sale are increasing at quite a higher speed. The evidence is normally stored between virtual and physical space, which not easy to be noticed after modified or destroyed. The investigations organizations should hold the most advanced technologies in order to stand in a more advantageous place to win this challenge. The physical storage media(hard drive, Pen drives, CF card and Flash Memory) may have conditions of physical damage, like head stack damage, malfunctioned motor, bad sector and circuit burnt, as well as logical damage, like accidental deletion, error copy, formation and virus attach, which cause the data lose. Therefore, the computer forensics technologies have become the most significance in judicature, with the factory-level technologies.?Data recovery technology is the one which helps to recover the data from the storage media, which result from data deletion, hacker attack, storage physical damage, circuit burnt, bad sector, head crash, etc. It helps the later phase of computer forensics and e-evidence collection. II. Data recovery technology become the “New Heights” of e-evidence studyAfter years of development, Electronic evidence technology has formed collection systems, documents, mail, database, storage, networks, and other multi-faceted technical system of electronic evidence, such electronic evidence technology system emphasis on building the operating system or network based upon data recovery and computer forensics, electronic evidence collection process in the affected systems and networks, and other third-party factors, the need to safeguard the relevant systems and networks to identify target data integrity is the premise.when it comes to recovery in physical damage of target storage carrier, Computer Forensics is subject to considerable limitations, so how to better evidence against defects in the target store data recovery, following the network, system, e-mail and other new techniques, computer forensics has become the new heights of modern technology.Part of the professional data recovery, computer forensics equipment have been applied to the current judicial field. Since2006, China’s public security, inspection, Economic Investigation, crime detection, network monitoring started to pay attention to the cutting-edge data recovery. Computer forensics technology, which gradually gained high recognition by its stability, security and functionality. China’s public security, inspection, Economic Investigation, crime detection, network monitoring and many other departments have set up assembly line with data recovery, computer forensics technology security system for electronic evidence, with which has gain fruitful results. Under support of National judiciary, the state-level high-tech enterprise, SalvationDATA, the world’ enterprise covering research. tech development, production and sales of data recovery tools, who has released series of computer forensics tool like HD Doctor, Data Compass, FLASH doctor.These tools has help First Research Institute of Ministry of Public Security of Guangdong Province Public Security Bureau, Guangzhou Municipal Public Security Bureau etc, successfully deployed a number of exclusive sets of data recovery, computer ‘With ten years consistent efforts, SalvationDATA technology and its brand has covered more than 60 countries through five continents market,data recovery tools from SalvationDATA have helped the United States Federal Bureau of Investigation, the Turkish police station, the Italian police station, and the Judicial Institute in Manchester to successfully set up data recovery and computer forensics technology system. There is no doubt that SalvationDATA has become the leading authority in modern data recovery and forensics solution.

III. Data recovery breakthrough the bottleneck of traditional electronic evidenceThe highly developed computer network crimes have a profound impact on the direction of the technological development so to face such situation, the judiciary must be continuously updated data recovery, computer forensics, electronic evidence cutting-edge technology platform to achieve the detection, analysis, evidence, evidence and other business development. As cyber crime has become increasingly prominent in computer, computer forensics technology will be the context of the judicial investigation computer electronic evidence of technical capability and response capability effective supplement. The computer forensics technology is based on original concept of the underlying technology, seamless compatibility with any data recovery, computer forensics system is characterized by the upper (For example: ENCASE / FTK / X-WAYS / analytical system / all kinds of identification systems, etc..),which can be effectively achieved with integration of the current data recovery, computer forensics data recovery. From The above analysis, we can easily see that the leading-edge data recovery, electronic evidence data acquisition, analysis, evidence and other business are in crucial need of computer forensics technology, And it certain that in the near future, the data recovery, computer forensics, electronic evidence technology will be applied to a wider range of flied.

July 14 2011

Communications, Broadband Internet, Computers, Computer, Computer Certification, Data Recovery, Hardware, Networks, Software

Tagged Under : , , , , , , , , , , , , , , , , , , , , , , , , , , , , , ,

Article by Moshiachy Thisyday

To earn your CCNA or CCNP certification, you’ve got to understand the basics of trunking. This is not just a CCNA topic – it’s essential to have a complicated understanding of trunking and etherchannels to move the BCMSN exam and earn your CCNP as well. Before we deal with those superior topics, though, it’s worthwhile to master the basics!

A trunk allows inter-VLAN visitors to move between immediately connected switches. By default, a trunk port is a member of all VLANs, so visitors for any and all VLANs can travel throughout this trunk. That includes broadcast site visitors!

The default mode of a swap port does differ between fashions, so always check your documentation. On Cisco 2950 switches, every single port is in dynamic fascinating mode by default, that means that every port is actively attempting to trunk. On these switches, the only motion wanted from us is to physically join them with a crossover cable. In just a few seconds, the port light turns inexperienced and the trunk is up and running. The command show interface trunk will confirm trunking.

How does the receiving change know what VLAN the body belongs to? The frames are tagged by the transmitting change with a VLAN ID, reflecting the number of the VLAN whose member ports should receive this frame. When the body arrives at the remote change, that change will look at this ID and then ahead the frame appropriately.

There are main trunking protocols it’s essential to understand and evaluate successfully, these being ISL and IEEE 802.1Q. Let’s check out the main points of ISL first.

ISL is a Cisco-proprietary trunking protocol, making it unsuitable for a multivendor environment. That’s one disadvantage, but there are others. ISL will place both a header and trailer onto the body, encapsulating it. This increases the overhead on the trunk line.

You know that the default VLAN is also referred to as the “native VLAN”, and another disadvantage to ISL is that ISL does not use the concept of the native VLAN. Which means that every single body transmitted across the trunk will likely be encapsulated.

The 26-byte header that’s added to the frame by ISL accommodates the VLAN ID; the 4-byte trailer comprises a Cyclical Redundancy Test (CRC) value. The CRC is a frame validity scheme that checks the frame’s integrity.

In flip, this encapsulation leads to one other potential issue. ISL encapsulation adds 30 bytes complete to the dimensions of the frame, potentially making them too massive for the switch to handle. (The maximum size for an Ethernet frame is 1518 bytes.)

IEEE 802.1q differs considerably from ISL. In distinction to ISL, dot1q doesn’t encapsulate frames. A four-byte header is added to the body, resulting in much less overhead than ISL. If the body is destined for hosts residing in the native VLAN, that header is not added. Because the header is barely four bytes in dimension, and is not even placed on each frame, using dot1q lessens the possibility of outsized frames. When the remote port receives an untagged body, the swap knows that these untagged frames are destined for the native VLAN.

Knowing the main points is the distinction between passing and failing your CCNA and CCNP exams. Maintain learning, get some fingers-on practice, and you’re in your approach to Cisco certification success!

BGP is without doubt one of the most complicated matters you’ll examine when pursuing your CCNP, if not essentially the most complex. I do know from personal expertise that when I was incomes my CCNP, BGP is the topic that gave me the most trouble at first. One thing I preserve reminding today’s CCNP candidates about, though, is that no Cisco technology is unimaginable to grasp for those who just break it down and understand the fundamentals before you start making an attempt to know the more advanced configurations.

BGP attributes are one such topic. You have bought well-identified necessary, well-known discretionary, transitive, and non-transitive. Then you definately’ve bought each particular person BGP attribute to recollect, and the order wherein BGP considers attributes, and what attributes even are… and a lot more! As with every other Cisco matter, we have to stroll before we can run. Let’s check out what attributes are and what they do in BGP.

BGP attributes are much like what metrics are to OSPF, RIP, IGRP, and EIGRP. You won’t see them listed in a routing table, but attributes are what BGP considers when selecting the perfect path to a destination when multiple legitimate (loop-free) paths exist.

When BGP has to decide between such paths, there’s an order by which BGP considers the trail attributes. For success on the CCNP exams, you’ll want to know this order. BGP looks at path attributes on this order:

Highest weight (Cisco-proprietary BGP worth)

Highest local preference (LOCAL_PREF)

Favor locally originated route.

Shortest AS_PATH is preferred.

Choose route with lowest origin code. Inner paths are most popular over exterior paths, and external paths are preferred over paths with an origin of “incomplete”.Lowest multi-exit discriminator (MED)

Exterior BGP routes most popular over Inside BGP routes.

If no external route, choose path with lowest IGP value to the following-hop router for iBGP.

Choose most recent route.

Select lowest BGP RID (Router ID).

If you do not know what these values are, or how they’re configured, do not panic! The subsequent several parts of this BGP tutorial will explain it all. So spend some time studying this order, and partly II of this free BGP tutorial, we’ll look at every of these values in detail. Preserve studying

May 03 2011

Linux file recovery software to avert critical data loss

Tagged Under : , , , , , , , , , , , , , , , , , , , , , , , , , , ,

Linux has gained enough popularity for its new and updated features. Usually, this operating system is considered as the most regularly upgraded application and hence, with Linux, many users feel that they are having the advantage of using the most recent technologies. Even some feel that Linux is free from virus attack and other data loss problems. However, it is the fact that the technology has nothing to do with data loss. Linux systems also undergo severe data loss situations, leaving the system drive completely inaccessible. Under such cases, you can take the help of any Linux data recovery software to retrieve your data back.

Data loss in Linux can be in any form, starting from the accidental/intentional deletion, formatting of the media, virus/malware attack, operating system malfunction, file system corruption or any other software/hardware contradiction etc.

Whatever, be the reason behind the failure of the Linux system, it is your valuable data in the media which suffers the most. Some data can be urgently required, some are the result of months of research work and some even can never be recreated. In such situations, loss of them caused severe business loss and mental trauma.

Among all the odds, if you have taken regular backups of your data, you always resides at the safe side and can restore the data from a recently taken valid backup. But, if you have not taken any recent backup, you are under serious trouble for sure.

But, among all these troubles of data loss, the good fact is that data from the troubled Linux drive never gets lost permanently. Therefore, if you can take strict measures to avoid overwriting the data in the drive, and run any efficient Linux file recovery utility, then, all you lost data can be easily recovered back.

These undelete Linux applications can work on any Linux operating system based computer system and can recover your lost, deleted, formatted or inaccessible data effectively. These utilities have been developed with many advanced scanning algorithms to dig into the storage media throughly and are completely read-only in nature. Moreover, with detailed instructions at every step and highly graphical user interfaces, they are pretty easy to use even with much technical knowledge.

April 19 2011

Corruption of Fstab and Mtab Files and Available Linux Recovery Solutions

Tagged Under : , , , , , , , , , , , , , , , , , , , , , , , , ,

However advanced the technology may be and whatever precautions we may take, data loss is almost inevitable. Though Linux operating system is often improved upon its previous versions than any of its counterparts, still there are a number of reasons, for which data can be lost in a Linux operating system based computer. In a Linux computer, the fstab (/etc/fstab) and mtab (/etc/fstab) are the two most crucial directories. Without these directories, the operating system could not be able to locate neither the existing hard drive volumes nor the mounted drives on your system. For this reason, the system fails to boot and all your data in the hard drive becomes inaccessible. In such situation of data loss, you need any Linux data recovery software to recover back the lost or inaccessible data.

Facts about ‘fstab’ and ‘mtab’ directories:

• The fstab or ‘file systems table’ is a system directory within the Linux operating system. This system configuration file contains information about all the available hard drives and volumes attached to the system. The file tells, the way, hard drive volumes are initialized and integrated through the file system. Moreover, it lists the details of the file systems, which are accessed by the ‘fsck command.

• The mtab or ‘mounted file systems table’ is also part of system configuration and lists all the currently mounted file systems on your Linux system. The file retains every detail of the mounted volumes, that is whether mounted manually or automatically and is automatically updated once the mount command is triggered against any drive or volume.

Sometimes, while accessing the Linux drives or the mounted volumes you may come across error messages related to the mounted file system and all the files and directories become inaccessible. The error message that you may have encountered can be read as below:

“Cannot read table of mounted file systems”

The above error is caused due to the corruption of ‘fstab’ or ‘mtab’ directories. Thus, the file system fails to mount and the data remains inaccessible thereof.

Such situation of data loss can only be dealt by any efficient Linux data recovery utility. These applications are meant to recover the lost, deleted, formatted or inaccessible data from the Linux file system based volumes. Moreover, these helpful utilities are completely safe to use and come with detailed instructions, so that can be used without any prior knowledge.

Incoming search terms for the article:

April 17 2011

How to Perform Linux Data Recovery

Tagged Under : , , , , , , , , , , , , , , , , , , , , , , ,

Linux is the UNIX like operating system that uses the Linux kernel of Monolithic type. The OS is being installed on a vast range of tablet computers, mobiles, video game consoles, mainframes, super computers etc. Even, statistics says that as, server OS, LINUX accounts more than 50% of the whole global installations. Also,over the years, Linux operating system has gained fair amount of popularity among the common home users with the Fedora, Ubuntu and OpenSUSE distributions. Moreover, with the egression of smart phones, netbooks etc, which are running on embedded LINUX, the operating system has been more closely used by many users. Though Linux has advanced technology and features, sometimes, some errors  lead to data loss or inaccessibility and you need to look for any Linux data recovery software to recover back your valuable data.

In day to day usage of a Linux system, there can be enormous possibility of data loss situations, and you may not always successful in trouble shooting the system to gain access of your data. Hence, if you don’t have a valid backup available or failed to restore the data from the backup, Linux recovery is the answer to bring back your data.

Common data loss situations in Linux:

Error – Mount wrong fs type, bad option, bad super block on /dev/hdb2.
Error – Too many mounted file systems.
File system error.
Grub Error 12 – Invalid device requested.
Grub Error  17 – Can not mount selected partition.

There can be many such errors leading to the loss or inaccessibility of your Linux data. In such cases, if you are a technical person, then you can trouble shoot at the low-level. You can  run the ‘fsck’ command to detect and fix such error. Prior to running the ‘fsck’ command, first, you need to go to the single user mode. Then, you have to unmount the file system partition, you are going to work upon, if it is not the root file system. If you don’t take enough care to unmount the file system, the ‘fsck warns you, such as- ‘The file system is mounted, do you want to continue anyway?’ Saying yes to the message, may result in the loss of your data, because, at times, ‘fsck’ writes directly to the disk.

If you need to check the root file system based partition, you have to boot the system in single user mode and run the ‘fsck’ with a ‘-b’ option so that it will run in a read-only mode. Also, the ‘-b’ option directly go to the ‘init’ and makes an emergency booting while skipping the other start-up scripts.

Sometimes, ‘fsck’ fails to run or exits without running at all. At that time, you need to force run the utility with ‘-f’ option. This is a case of severe corruption and you need to give additional information to ‘fsck’, such as the size of the alternate superblock or the address of the superblock to fetch the data and fix the error.

However, sometimes, these low-level recovery process is tedious as well as risky with respect to your valuable data. Hence, you can go for any Linux data recovery software, which can recover the data for you safely.

April 02 2011

Linux Hard Drive Crash And Linux Data Recovery

Tagged Under : , , , , , , , , , , , , , , , , , , , , , , , , ,

Linux is a popular operating system, known as an actual techies’ operating system. The robust architecture and open source coding of the operating system insures that it can’t be affected by viruses and other malicious programs easily.

However, even the Linux is prone to situations where you may lose hard drive volumes and data. Hard drive crash is one such kind of situation that leads to significant data loss and needs Linux Hard Drive Recovery to be sorted out.

The hard drive crash is a situation where you cannot access your data from a properly configured system, however the data is still there. The hard drive may get crashed during normal computer operations, or because of external reasons, like power outages and heat. You must have an effective backup plan to save your data, but if it is not available; commercial recovery software and services are required to overcome the problem.

Linux hard drive may crash due to numerous reasons, which are broadly categorized into two major groups: Logical Failure and Physical Failure. Irrespective of the cause of hard drive crash, your data is still recoverable from Linux hard drive.

Symptoms of Linux hard drive crash

Computer is unresponsive or unbootable.

You encounter error messages, which indicates hard drive is unrecognized.

Black screen at start up.

Grinding or clicking sounds coming from hard drive.

System generally stops responding, restarts, or you cannot run any application.

Error messages related to missing or damaged data structures, like file system and Superblock.

When you encounter any of the above situations with your Linux computer, the very first thing that you need to do is determine the type of problem. Whether it is logical failure or it’s caused by breakdown of mechanical hard drive components.

In case of logical hard drive failure, you can recover lost data in a quick and easy way through Linux hard drive recovery software. The applications carry out extensive scan of whole hard drive using advanced scanning methods and extract all lost, missing, and inaccessible data from it.

Stellar Information Systems Limited is the foremost provider of both types of Linux Hard Drive Recovery solutions. The software is able to recover data from Ext4, Ext3, Ext2, FAT12, FAT16, and FAT32 file system volumes of all major Linux distributions.

April 01 2011

How to Perform Ext4 File Recovery in Linux

Tagged Under : , , , , , , , , , , , , , , , , , , , , , , ,

The Ext4 (Fourth Extended File System) is an advanced journaling file system, developed for Linux operating system. It is successor of Ext3 file system. Ext4 has removed the 64-bit limits of Ext3 file system as it was developed as series of the backward compatible extensions. It has great stability and performance features, which make it more powerful than earlier file system of Linux operating system.

The journaling feature of Ext4 file system prevents file loss and need of Linux Data Recovery solutions, in case of system crash and unexpected system shutdown.

Under some circumstances, you may lose your valuable files from the Ext4 file system volume due to numerous reasons. The reason could be anything like-

• Accidental deletion of the important files.

• Formatting of Ext4 file system volumes unintentionally or intentionally.

• File system corruption.

• Virus infection or damage caused by other malicious programs.

In such cases, you must have an absolute backup of your valuable files. However, if the backup is not available, you face serious file loss situations and need Data Recovery Linux to work around the problem.

Recover Lost Linux Files Using Extundelete Utility

The extundelete is a command-line utility in Linux operating system, which helps you to recover lost or deleted files from Ext4 file system volumes. This utility uses the significant information stored in journal of Linux hard drive volume for retrieving the lost or deleted files. It works only on the Ext4 and Ext3 file system volumes.

This command-line tool is capable of recovering both the file names and contents of the deleted files. It is able to retrieve a deleted file just after parsing journal file. The utility is developed to perform in a fast way when you have to recover the files from large Ext4 file system volumes.

Although, extundelete utility works pretty effectively in various file loss situations, but it cannot handle situations like file system corruption and hard drive formatting. At this point, Ext4 Recovery software come for your help.

These are powerful and advanced third-party tools, which carry out in-depth scan of entire hard drive and extract all lost, missing, and inaccessible data from it. They perform quick, easy, and safe Linux Recovery in all data loss situations, with interactive user interface and read-only behavior.

Stellar Phoenix Linux Data Recovery software recovers lost Linux files from hard drive, USB drive, and network mapped volumes. It supports recovery from Ext4, Ext3, Ext2, FAT32, FAT16, and FAT12 file system volumes. The software works well with all major distributions of Linux operating system, including Red Hat, SUSE, Debian, Mandriva, and Ubuntu.