INSERT linux

cbrookerd

Junior Member
Jan 5, 2005
7
0
0
alright.....i heard about this little live cd that supposedly has some useful recovery tools built in called INSERT.......the main interest i had in this was it's built in antivirus (Clam Antivirus).....i would like to use this bootable cd to go in and scan a system for virus' on a windows machine.....how would i go about doing this?.....i read the documentation on there webpage (www.insert.cd), but it was not all that helpful.....i am fairly familiar w/linux but i'm no guru....thnx for any help
 

Randabis

Member
Dec 26, 2004
55
0
0
If it supports it, you probably have to mount the windows partititon(s) and then have the scanner scan them.
 

drag

Elite Member
Jul 4, 2002
8,708
0
0
There are a few live linux cdrom-based distros like that.

Try out Knoppix STD


It's a 'security' version of the popular Knoppix live-linux desktop cdrom.

It has all the security assesment tools you could imagine that can fit on a cdrom.

features/programs

ClamAV
Password crackers
network sniffers
network scanners
traffic monitors
tcpdump
packet generators
encrypted tunnelling programs
wireless tools
forensic tools
limited ntfs support
tools to reset passwords on Windows OSes (even administrator passwords)
All sorts of other fun and usefull stuff.

Most everything should be detected and setup automaticly on boot time.
 

drag

Elite Member
Jul 4, 2002
8,708
0
0
if it ends up that you need to mount partitions to scan them it goes like this on teh command line.

Each harddrive and partition has a file name associated with it. No c: drives or anything like that.

The harddrive names go like this:
/dev/hda (primary master)
/dev/hdb (primary slave)
/dev/hdc (secondary master)
/dev/hdd (secondary slave)

then each partition has a number associated with it and it's name is it's number added onto the name of the harddrive.

For instance /dev/hdc2 would be the second partition on the secondary slave ide device.

If you have SATA devices it may mess up the naming a bit.
you can find out details about the setup thru the dmesg command, and you filter it thru the grep command to filter out stuff that your not looking for.
dmesg |grep hd

and that should tell you some stuff. Alternately you can go to /proc/ide and there are directories their that include details about your avaible drives, like model and media type (like disk vs cdrom).

In Linux there is no C drive or anything such thing. You have one directory tree, with a root. Root = /
Everything you have access to is part of that tree, all file systems either on a network, ramdisks, dvd disks, harddrives, or whatnot have to be mounted to a directory on that directory tree for you to access it.

knoppix should automaticly detect and mount partitions for your conveinence. You can see the currently mounted file systems with the /etc/mtab file.

The easy way to see the contents of files is with the cat command.

cat /etc/mtab

that will show you what is mounted.

knoppix (I think) will mount things to the /mnt directory. Like /mnt/hda1. Inside that directory will be the contents of your harddrive partitions.

to manually mount a file system you make a directory and then mount the partition to it.
mkdir /mnt/harddrive
mount /dev/hda1 /mnt/harddrive

to move to a directory you go:
cd /mnt/harddrive

to scan all file and directories go like this:
cd /mnt
freshclam
clamscan -ri

freshclam updates the virus definitions and clamscan will scan the directories.

The -ri is command options and the -r tells it to do it recursively (descend into directories, otherwise it only scans current directory) and the -i tells it to only print out infected files. If you want to see the progress as it runs just go:
clamscan -r

it can take a LONG time to finish scanning.

It will give you a summary when it's finished.

Hope that helps
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |