Wednesday October 8, 2008 5:18 PM AEST
Latest Comments
"Good"
by Francis Ayitey | Oct 6, 2008 10:48 AM
 
"With regard to the battle against cybercrime, Kaspersky Labs, the creator of the famous and ..."
by Mr. Anonymous | Oct 4, 2008 9:08 AM
 
"It does not matter whether the test relies on signature-based testing instead of heuristics, or ..."
by Tony | Oct 3, 2008 8:47 AM
 
"Makes me wonder about other so called off-site mail clients"
by Peter | Oct 3, 2008 12:33 AM
 
"eBay has become unbearable for so many reasons. Some sellers are regrouping at a new internation..."
by Jenny | Oct 2, 2008 9:43 PM

STRSRCH and URL_SRCH

  • Email a Friend
  • Print Page
STRSRCH and URL_SRCH
Product Info
Supplier:
Product Rating
Features:  3
Ease of Use:  2
Performance:  5
Documentation:  4
Support:  4
Value for Money:  5
Overall Rating:  Overall Rating
 
For: A fast way to perform basic searches
Against: Many all-in-one utilities provide the same functionality
Verdict: For forensic toolkits on a budget these utilities are a fit
By Justin Peltier
May 22, 2008 3:19 PM
Tags: STRSRCH | and | URL_SRCH
Many multifunction utilities such as AccessData's Forensic Toolkit include similar functionality, but STRSRCH and URL_SRCH are purported to be faster.

The commands can be a bit confusing to the first-time user as both STRSRCH and URL_SRCH use many switches. The basic command structure for STRSRCH is strsrch -p c:\ -s string.fle -o d:output.fle, which makes the utility search the entire C: drive for anything listed in the string.fle file. The resulting output is stored on d: in a file named output.fle.

The basic command structure for URL_SRCH is URL_SRCH-p d:\path -o c:\tmp\output -w -m 200 -d "|". This command searches the d:\path directory and all subdirectories for URLs, IPs and email addresses.

When found the results are stored in a wide format with a maximum length of 200 characters and separated by the pipe symbol "|".

The greatest advantage to the utilities is the cost. These utilities can be used as an inexpensive way to search large firewall, router or intrusion detection/intrusion prevention log files for specific strings.

For example, a search can be run against a content filter system for inappropriate words for use in an internet abuse investigation. The same strings can be used against a Check Point firewall log to look for access to inappropriate images, or even to search a local system for the same. Also, these utilities can be combined with the free AccessData Forensic Imager to create an inexpensive toolkit.

There are help files included on the website for download and purchase of the utilities. Each is quite lengthy and covers most if not all command-line options.

The developers say that as of April 2008 all Maresware software will be shipping via a CD-Rom and a licence dongle. The dongle is only used to initialise the software with ownership information to prevent software theft. This has been reflected in the purchase price.

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
Complete the SC Reader Survey for your chance to win an iPhone!
 
 
 
Biometrics & Forensics Whitepapers