08-30-2010
It does precisely what hergp suggested: "Writing a kernel module which intercepts the unlink system call and places the files to be deleted in the recycle bin".
The recycle bin is /var/tmp/trashcan. Every deleted file is placed there suffixed by its deletion date.
A log file, /var/tmp/trashcan/log, is telling who deleted what and when.
9 More Discussions You Might Find Interesting
1. UNIX for Dummies Questions & Answers
I just set up an ftp server with Red Hat 5.2. I am doing the work, I'm baby stepping, but it seems like every step I get stuck. Currently, I'm trying to set up a crontab job, but I'm getting the following message: /bin/sh: /usr/bin/vi: No such file or directory. I see that vi exists in /bin/vi,... (3 Replies)
Discussion started by: kwalter
3 Replies
2. UNIX for Dummies Questions & Answers
Hi All,
Can somebody tell me the difference between /bin, /usr/bin, /sbin ?
Thanx in advance,
Saneesh Joseph (3 Replies)
Discussion started by: saneeshjose
3 Replies
3. Solaris
I have a person running a perl script that is parsing > 2G log files and pipes to cut -d " " -f 1,6,7,8...
The script itself is in a nfs mounted home directory. It runs fine when started from a solaris 8 box but fails after about 400 lines when started from the solaris 10 box. The solaris... (1 Reply)
Discussion started by: wottie
1 Replies
4. Solaris
Hi all,
below is the problem details:
ora10g@CNORACLE1>which ld
/usr/ucb/ld
ora10g@CNORACLE1>cd /usr/ccs/bin
ora10g@CNORACLE1>ln -s /usr/ucb/ld ld
ln: cannot create ld: File exists
ora10g@CNORACLE1>
how to link it to /usr/ccs/bin? (6 Replies)
Discussion started by: SmartAntz
6 Replies
5. UNIX for Advanced & Expert Users
hi i have some perl scripts with shebang line as (#! /usr/bin/env perl ) instead of actual absolute path of perl ( i know why its that way ) everything works fine from command line , the problem is when i am trying to run those scripts from web ( local web tool ) it throws error as /usr/bin/env :... (6 Replies)
Discussion started by: zedex
6 Replies
6. UNIX for Dummies Questions & Answers
Hi!
All the basic linux commands, ie. echo, find, etc, are located in /bin. I have a couple of programs that have these commands pointed towards /usr/bin, ie, /usr/bin/echo (even though the actual 'echo' command is in /bin). How can I alias or redirect or link the /usr/bin to /bin just for this... (6 Replies)
Discussion started by: dancerat
6 Replies
7. OS X (Apple)
Q1. I understand that /usr/local/bin means I can install/uninstall stuff in here and have any chance of messing up my original system files or effecting any other users. I created this directory myself.
But what about the directory I didn't create, namely /Users/m/bin? How is that directory... (1 Reply)
Discussion started by: michellepace
1 Replies
8. Solaris
Hi Experts,
I found that the same commands(sort, du, df, find, grep etc.) exists in both dir.
What is the difference to use them?
i.e: to use xpg4/bin/grep and usr/bin/grep
My OS version is SunOS 5.10
Regards,
Saps (7 Replies)
Discussion started by: saps19
7 Replies
9. BSD
I'm not sure if this is the default behavior for the ld command, but it does not seem to be looking in /usr/local/lib for shared libraries.
I was trying to compile the latest version of Kanatest from svn. The autorgen.sh script seems to exit without too much trouble:
$ ./autogen.sh
checking... (2 Replies)
Discussion started by: AntumDeluge
2 Replies
LEARN ABOUT DEBIAN
rifiuti2
RIFIUTI2(1) A MS Windows recycle bin analysis tool RIFIUTI2(1)
NAME
rifiuti2 - A MS Windows recycle bin analysis tool
SYNOPSIS
rifiuti [ -x ] [ -tnl8 ] [ -o outfile ] filename
rifiuti-vista [ -x ] [ -n8 ] [ -o outfile ] file_or_directory
DESCRIPTION
Rifiuti2 is a rewrite of rifiuti, a great tool from Foundstone folks for analyzing Windows Recycle Bin INFO2 file. Analysis of Windows
Recycle Bin is usually carried out during Windows computer forensics. Rifiuti2 can extract file deletion time, original path and size of
deleted files and whether the deleted files have been moved out from the recycle bin since they are trashed. Rifiuti2 supports the INFO2
file format found in Windows up to Windows XP and the new file format found in Vista, and the program is fully internationalized. If you
need to analyse recycle bins of Windows Vista and Windows Server 2008, you should use the rifiuti-vista command, for other Windows plat-
forms, you should use the rifiuti command.
Quoting from original Foundstone page:
Many computer crime investigations require the reconstruction of a subject's Recycle Bin. Since this analysis technique is executed
regularly, we researched the structure of the data found in the Recycle Bin repository files (INFO2 files). Rifiuti, the Italian
word meaning "trash", was developed to examine the contents of the INFO2 file in the Recycle Bin. ... Rifiuti is built to work on
multiple platforms and will execute on Windows (through Cygwin), Mac OS X, Linux, and *BSD platforms."
Since the original rifiuti (last updated 2004) is restricted to English version of Windows (fail to analyze any non-latin character), thus
this rewrite. But it does more:
* Supports Windows in any other languages besides English
* Supports Vista and 2008 (they don't use INFO2 file any more)
* Enables localization (that is, translatable)
* More rigorous error checking
* Supports output in XML format
OPTIONS
These are plain text output options:
-t --delimiter=STRING
String to use as delimiter (TAB by default)
-n --no-heading
Don't show header
-l --legacy-filename
Show legacy filename instead of unicode
-8 --always-utf8
Always show file names in UTF-8 encoding
These are general application Options:
-o --output=FILE
Write output to FILE
-x --xml
Output in XML format (-t, -n, -l, -8 options will have no effect)
--from-encoding=ENC
The assumed file name character set when no unicode file name is present in INFO2 record (mandatory if INFO2 file is created by
Win98, useless otherwise)
COPYRIGHT
Part of the work of Rifiuti2 is derived from Rifiuti, both pieces of software are licensed under the simplified BSD license.
AUTHOR
The main author of Rifiuti2 is Abel Cheung, and Anthony Wong helps in some packaging and documentation work (like this manpage). The orig-
inal author of Rifiuti is Keith J Jones.
0.5.0 2008-11-21 RIFIUTI2(1)