Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security FullDisclosure
[Top] [All Lists]

RE: [Full-Disclosure] Imaging Operating Systems

Subject: RE: [Full-Disclosure] Imaging Operating Systems
Date: Thu, 27 May 2004 09:22:28 -0500
VMWare is a great way to go. You get a quarantined "guest" OS that you can 
restore by simply replacing a file. You can also take a "snapshot" of the OS 
and then just revert to that snapshot anytime you like. You can also set up a 
private LAN that is isolated to your test computer for multiple guest Oses - 
lets you watch how the applications want to communicate.

Baseline system -> Snapshot -> Do Bad Thing -> Rebaseline -> Revert to snapshot 
and Compare baselines -> Repeat as needed

- Tom Chmielarski



-----Original Message-----
From: full-disclosure-admin@lists.netsys.com 
[mailto:full-disclosure-admin@lists.netsys.com] On Behalf Of James Riden
Sent: Wednesday, May 26, 2004 4:24 PM
To: mbs@mistrealm.com
Cc: Full-Disclosure
Subject: Re: [Full-Disclosure] Imaging Operating Systems


Michael Schaefer <mbs@mistrealm.com> writes:

Hi all

We are building a Windows test system, to try out tool bars, spy ware, 
malware and trojans on.

Once we learn what we need to know, we obviously want to get rid of 
the junk quickly and cleanly.

I keep hearing suggestions about having a "clean image" to transfer 
onto the computer.

Can anyone send some details?

Ghost or Altiris can do this for you.

-- 
James Riden / j.riden@massey.ac.nz / Systems Security Engineer Information 
Technology Services, Massey University, NZ. GPG public key available at: 
http://www.massey.ac.nz/~jriden/

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


<Prev in Thread] Current Thread [Next in Thread>