11. Boot from a clean medium — Live CDs

To make a proper investigation of a machine that may have been rooted you need to boot from clean media. One option is to physically move the system disk from the hacked machine to another machine and mount it as a slave. A simpler way is to boot the machine from a "live CD". Suitable CDs include:

There are many others.

...previousup (conts)next...



About this document:

Produced from the SGML: /home/umits/public_html/_unix_security/_reml_grp/diagnostic_forensic_tools.reml
On: 23/10/2005 at 13:29:12
Options: reml2 -i noindex -l long -o html -p multiple