Showing posts with label Ubuntu. Show all posts
Showing posts with label Ubuntu. Show all posts

Thursday, May 14, 2009

Using Foremost

Foremost Syntax

foremost [-h][-V][-d][-vqwQT][-b][-o

] [-t][-s][-i]

Available Options

-h Show a help screen and exit.
-V Show copyright information and exit.
-d Turn on indirect block detection, this works well for Unix file systems.
-T Time stamp the output directory so you don’t have to delete the output dir when running multiple times.
-v Enables verbose mode. This causes more information regarding the current state of the program to be dis-played on the screen, and is highly recommended.
-q Enables quick mode. In quick mode, only the start of each sector is searched for matching headers. That is,the header is searched only up to the length of the longest header. The rest of the sector, usually about 500 bytes, is ignored. This mode makes foremost run con- siderably faster, but it may cause you to miss files that are embedded in other files. For example, using quick mode you will not be able to find JPEG images embedded in Microsoft Word documents.

Quick mode should not be used when examining NTFS file systems. Because NTFS will store small files inside the Master File Table, these files will be missed during quick mode.

-Q Enables Quiet mode. Most error messages will be sup-pressed.
-w Enables write audit only mode. No files will be extracted.
-a Enables write all headers, perform no error detection in terms of corrupted files.
-b number Allows you to specify the block size used in foremost. This is relevant for file naming and quick searches. The default is 512. ie. foremost -b 1024 image.dd

-k number Allows you to specify the chunk size used in foremost.This can improve speed if you have enough RAM to fit the image in. It reduces the checking that occurs between chunks of the buffer. For example if you had > 500MB of RAM. ie. foremost -k 500 image.dd

-i file The file is used as the input file. If no input file is specified or the input file cannot be read then stdin is used.

-o directory Recovered files are written to the directory directory.

-c file Sets the configuration file to use. If none is speci-fied, the file “foremost.conf” from the current direc-tory is used, if that doesn’t exist then “/etc/fore-most.conf” is used. The format for the configuration file is described in the default configuration file included with this program. See the CONFIGURATION FILE section below for more information.

-s number Skips number blocks in the input file before beginning the search for headers. ie. foremost -s 512 -t jpeg -i /dev/hda1

Foremost examples

Search for jpeg format skipping the first 100 blocks

sudo foremost -s 100 -t jpg -i image.dd

Only generate an audit file, and print to the screen (verbose mode)

sudo foremost -av image.dd

Search all defined types

sudo foremost -t all -i image.dd

Search for gif and pdf

sudo foremost -t gif,pdf -i image.dd

Search for office documents and jpeg files in a Unix file sys-tem in verbose mode.

sudo foremost -v -t ole,jpeg -i image.dd

Run the default case

sudo foremost image.dd

image.dd means you need to enter your hardisk mount point i.e /dev/sda1 or /dev/sda2

Recover deleted files in Linux

Although there's no common "undelete" command for a Linux EXT3 file system, you can recover many types of accidentally erased files, including documents, graphics, and system files using the "Foremost" console application.

When you delete a file, the data is not really overwritten. The pointer in the filesystem to the file is simply removed so the disk area can be overwritten when necessary. The more the disk is written to after the file is deleted, the larger the chance it will be overwritten and become unrecoverable.


Foremost is a command line utility for finding and recovering deleted files based on their type. It was origionally developed for the US Air Force Office of Special Investigations. It can recover files from a number of filesystems, including fat, ext3 and NTFS. It can be installed and run from the live cd.

Foremost can recover files with the following extensions:
jpg, gif, png, bmp, avi ,exe, mpg, wav, riff, wmv, mov, pdf, ole, Excel, Access, doc, zip, XML, SXW, SXC, SXI, SX, rar, htm, cpp

For other file extensions we may need to edit /etc/foremost.conf which can be found in man page of Foremost (man foremost)

How to Install:

Enable the universe repository and install foremost:

sudo apt-get install foremost

Assuming the lost files are on a USB drive (sda), you need to create a writeable directory on another drive where you can put the recovered files

sudo mount /dev/sdb1 /recovery
sudo mkdir /recovery/foremost

And then run foremost:

sudo foremost -i /dev/sda -o /recovery/foremost

or for specific file format e.g. video (avi):

sudo foremost -t avi -i /dev/sda -o /recovery/foremost

The recovered files will then be owned by root. Change their ownership so that you can use them:

sudo chown -R youruser:yourgroup /recovery/foremost



Please note that there's no guarantee that foremost will succeed in recovering your files, but at least there's a chance.


Friday, April 24, 2009

Upgrading to Ubuntu 9.04 From 8.10 (Desktop)


Here is the tutorial for upgrading Ubuntu 8.10 (Intrepid Ibex) desktop to latest Ubuntu Linux 9.04 (Jaunty Jackalope) over the Internet.

Ubuntu Linux support direct upgrade Ubuntu 9.04 from Ubuntu 8.10.

Make sure you have all updates applied to Ubuntu 8.10 before you start upgrade. To do this visit:
System -> Administration -> Update Manager







Ubuntu Update Manager

Click on "Install Updates"

Network Upgrade for Ubuntu Desktops over the Network

You can easily upgrade over the network as follows:

Visit System > Administration > Update Manager




Click the Check button to check for new updates.

A message will appear informing you of the availability of the new release.

Click Upgrade.

Follow the on-screen instructions.

Upgrade Ubuntu Server 8.10 to 9.04

ubuntu logo

You can upgrade the server either from console or from network remotely.
Server
Be sure that you have all updates applied to Ubuntu 8.10 server before you upgrade. Type the following command to apply updates:
$ sudo apt-get update
$ sudo apt-get upgrade

WARNING! Backup important data, sql and configuration file before server running the following upgrade commands. The following discussion only applies to the SERVER edition. For Ubuntu 9.04 desktop upgrade click here.

Next, install update-manager-core if it is not already installed:
$ sudo apt-get install update-manager-core


Finally, start the upgrade tool, enter:

$ sudo do-release-upgrade


Now, just follow the on-screen instructions to upgrade your server over ssh session.

Monday, April 20, 2009

How to mount ISO image

Like anything else on linux, it's easiest to do things from the command line. Open up a terminal window and type in the following commands

sudo mkdir /media/iso

sudo modprobe loop

sudo mount -t iso9660 -o loop filename.iso /media/iso

You should be able to navigate to the /media/iso folder and see the contents of the ISO image. If you want to unmount the iso, use the following command:

sudo umount /media/iso

Usage:

modprobe loop

-> loads/ installs the module for loopback file system support
iso9660

-> the file system of CD Roms
-t

-> specify the file system type
-o loop

-> for additional options while using a loopback filesystem

Set Default Terminal Emulator

Ubuntu has a number of terminal emulators that you can use, including xterm and the gnome terminal. If you install the kubuntu desktop package you can also use konsole under ubuntu.

Setting the default terminal emulator is easy by using the update-alternatives command. Open a terminal window and type in the following command:

$ sudo update-alternatives –config x-terminal-emulator

You'll see something similar to the following, although you may not see as many options on your system:

$ sudo update-alternatives –config x-terminal-emulator

There are 7 alternatives which provide `x-terminal-emulator'.

Selection Alternative
———————————————–
1 /usr/bin/xterm
2 /usr/bin/uxterm
3 /usr/bin/koi8rxterm
4 /usr/bin/lxterm
*+ 5 /usr/bin/gnome-terminal.wrapper
6 /usr/bin/konsole
7 /usr/bin/xfce4-terminal.wrapper

Press enter to keep the default[*], or type selection number:

Just type in the number of the selection and hit enter. Now when you launch the terminal via the menu item, or by typing in x-terminal-emulator at the command line, you will see the correct window pop up.

Watch Movies in Your Linux Terminal Window

In the era of high definition videos everywhere (Metacafe, YouTube, etc.), only the truly linux junkie would decide to watch their movies in ASCII text in a terminal window. The surprising thing is that some videos are even fairly watchable.


image


I've found that cartoons work best because of the limited detail.

Watch Movies in ASCII

The first thing you'll want to do is make sure that mplayer is installed, which is easy enough from the command line:

sudo apt-get install mplayer

Then, to actually watch the movies from a terminal window, use the following syntax, replacing MovieName with the filename of your video.

mplayer -vo caca MovieName.avi

The "caca" command is actually the color text driver - you could also use " -vo aa " instead for black & white, but that would just be silly.


image


These screenshots don't really do it justice - it's seriously just as bad when you're watching.


image


Sequences with a lot of contrast work better…


image


And it wouldn't help to sit about 8 feet back from the monitor.


image


Now that was truly a Stupid Geek Trick!

Customized Welcome Banner in Ubuntu

Every time I connect to my Ubuntu server through putty, I get to see the default message which is kind of scary.
Here's the message that I get every time:

Linux trap 2.6.9-67.0.1.ELsmp #1 SMP Fri Nov 30 11:51:05 EST 2007 i686 i686 i386 GNU/Linux

The programs included with the Ubuntu system are free software;
the exact distribution terms for each program are described in the
individual files in /usr/share/doc/*/copyright.

Ubuntu comes with ABSOLUTELY NO WARRANTY, to the extent permitted by
applicable law.

Last login: Mon Aug 13 01:05:46 2007 from XX.XX.XX.XX

nix@trap:~$


Changing this message requires editing two different files. The first three sections can be modified by editing the following file:

/etc/motd


This file contains the linux build number as well as the Ubuntu warranty message. I don't find this particularly useful, so I removed all of it and replaced it with my own message.

To disable the last login message (which I don't recommend doing), you will need to edit the following file in sudo mode:

/etc/ssh/sshd_config


Find this line in the file and change the yes to no as shown:

PrintLastLog no


Now when you login, you'll get a blank prompt, although I wouldn't necessarily recommend it because it's useful to see the last login to the system for security reasons. This is my prompt now:

This is development system.

Last login: Mon Apr 20 12:47:36 2009 from XX.XX.XX.XX
nix@trap:~$

Friday, March 27, 2009

Ubuntu 9 to be out Soon

Well when it comes to user friendly Linux first thing which comes to my mind is Ubuntu. I have been following Ubuntu religiously since the start of my career.



There are plenty of features which makes it stand apart from its Cousins which includes a large community backing up to provide every possible application operative on this debian platform, further to that deployment of these are also pretty easy, thanks to Aptitude and Synaptic . I have been running it successfully on HP and Dell laptops in my office, with Wi-LAN working like a charm, which is a bit of screwy when it comes to distributions other than Ubuntu.

Waiting anxiously to get my hands on 9.04