From 222c709ec9a11d286a77187d25dd6ca6b43d9328 Mon Sep 17 00:00:00 2001 From: Daniel Black Date: Wed, 26 Jan 2005 02:44:04 +0000 Subject: Initial import. Package-Manager: portage-2.0.51-r15 --- app-forensics/mac-robber/ChangeLog | 8 ++++++ app-forensics/mac-robber/Manifest | 14 ++++++++++ .../mac-robber/files/digest-mac-robber-1.00 | 1 + app-forensics/mac-robber/mac-robber-1.00.ebuild | 31 ++++++++++++++++++++++ app-forensics/mac-robber/metadata.xml | 24 +++++++++++++++++ 5 files changed, 78 insertions(+) create mode 100644 app-forensics/mac-robber/ChangeLog create mode 100644 app-forensics/mac-robber/Manifest create mode 100644 app-forensics/mac-robber/files/digest-mac-robber-1.00 create mode 100644 app-forensics/mac-robber/mac-robber-1.00.ebuild create mode 100644 app-forensics/mac-robber/metadata.xml (limited to 'app-forensics/mac-robber') diff --git a/app-forensics/mac-robber/ChangeLog b/app-forensics/mac-robber/ChangeLog new file mode 100644 index 000000000000..bee57432a5d1 --- /dev/null +++ b/app-forensics/mac-robber/ChangeLog @@ -0,0 +1,8 @@ +# ChangeLog for app-forensics/mac-robber +# Copyright 1999-2005 Gentoo Foundation; Distributed under the GPL v2 +# $Header: /var/cvsroot/gentoo-x86/app-forensics/mac-robber/ChangeLog,v 1.1 2005/01/26 02:44:04 dragonheart Exp $ + + 26 Jan 2005; Daniel Black + +mac-robber-1.00.ebuild, +metadata.xml: + Initial import. Suggested by Michael Zanetta . + diff --git a/app-forensics/mac-robber/Manifest b/app-forensics/mac-robber/Manifest new file mode 100644 index 000000000000..bfed45f4904a --- /dev/null +++ b/app-forensics/mac-robber/Manifest @@ -0,0 +1,14 @@ +-----BEGIN PGP SIGNED MESSAGE----- +Hash: SHA1 + +MD5 a742d22730e4acb79860592cf304c7a7 mac-robber-1.00.ebuild 726 +MD5 1e9937a862e19cdf3f8b0838c48c2ce5 metadata.xml 1434 +MD5 abf9fc83ec8c2163c7878770832de2df ChangeLog 392 +MD5 df98bdff9227fef4cff867355797b655 files/digest-mac-robber-1.00 66 +-----BEGIN PGP SIGNATURE----- +Version: GnuPG v1.4.0 (GNU/Linux) + +iD8DBQFB9wP6mdTrptrqvGERAip1AKCKuUqbjHDmZPsDSKziFmeLoZ13tgCfVDK9 +E0QmRFpbLe/WNmysMbMLAQ4= +=53Wq +-----END PGP SIGNATURE----- diff --git a/app-forensics/mac-robber/files/digest-mac-robber-1.00 b/app-forensics/mac-robber/files/digest-mac-robber-1.00 new file mode 100644 index 000000000000..4eb547f91a21 --- /dev/null +++ b/app-forensics/mac-robber/files/digest-mac-robber-1.00 @@ -0,0 +1 @@ +MD5 902afd8e6121e153bbc8cb93013667fd mac-robber-1.00.tar.gz 11483 diff --git a/app-forensics/mac-robber/mac-robber-1.00.ebuild b/app-forensics/mac-robber/mac-robber-1.00.ebuild new file mode 100644 index 000000000000..d24b835bf24d --- /dev/null +++ b/app-forensics/mac-robber/mac-robber-1.00.ebuild @@ -0,0 +1,31 @@ +# Copyright 1999-2005 Gentoo Foundation +# Distributed under the terms of the GNU General Public License v2 +# $Header: /var/cvsroot/gentoo-x86/app-forensics/mac-robber/mac-robber-1.00.ebuild,v 1.1 2005/01/26 02:44:04 dragonheart Exp $ + +inherit toolchain-funcs + +DESCRIPTION="mac-robber is a digital forensics and incident response tool that collects data" +HOMEPAGE="http://www.sleuthkit.org/mac-robber/index.php" +SRC_URI="mirror://sourceforge/${PN}/${P}.tar.gz" + +LICENSE="GPL-2" +SLOT="0" +KEYWORDS="x86" +IUSE="" + +DEPEND="virtual/libc" + + +src_compile() { + emake CC="$(tc-getCC)" GCC_OPT="${CFLAGS}" \ + || die "make failed" +} + +src_test() { + ./mac-robber -V || die "test failed" +} + +src_install() { + dobin mac-robber + dodoc README +} diff --git a/app-forensics/mac-robber/metadata.xml b/app-forensics/mac-robber/metadata.xml new file mode 100644 index 000000000000..39c63700da50 --- /dev/null +++ b/app-forensics/mac-robber/metadata.xml @@ -0,0 +1,24 @@ + + + +forensics + + forensics@gentoo.org + Forensics Herd + + +mac-robber is a digital forensics and incident response tool that collects data from allocated files in a mounted file system. +The data can be used by the mactime tool in The Sleuth Kit to make a timeline of file activity. The mac-robber tool is based on +the grave-robber tool from TCT and is written in C instead of Perl. + +mac-robber requires that the file system be mounted by the operating system, unlike the tools in The Sleuth Kit that process the +file system themselves. Therefore, mac-robber will not collect data from deleted files or files that have been hidden by +rootkits. mac-robber will also modify the Access times on directories that are mounted with write permissions. + + +"What is mac-robber good for then", you ask? mac-robber is useful when dealing with a file system that is not supported by The +Sleuth Kit or other forensic tools. mac-robber is very basic C and should compile on any UNIX system. Therefore, you can run +mac-robber on an obscure, suspect UNIX file system that has been mounted read-only on a trusted system. I have also used +mac-robber during investigations of common UNIX systems such as AIX. + + -- cgit v1.2.3-65-gdbad