<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for IR and forensic talk</title>
	<atom:link href="http://blog.kiddaland.net/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.kiddaland.net</link>
	<description>Some useless talk mixed with hopefully interesting points every now and then</description>
	<lastBuildDate>Thu, 15 Jul 2010 14:48:53 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
	<item>
		<title>Comment on log2timeline Version 0.50 Released by Digital Forensics Case Leads: Ann’s Aurora Edition &#124; Portable Digital Video Recorder</title>
		<link>http://blog.kiddaland.net/2010/06/log2timeline-version-0-50-released/comment-page-1/#comment-4330</link>
		<dc:creator>Digital Forensics Case Leads: Ann’s Aurora Edition &#124; Portable Digital Video Recorder</dc:creator>
		<pubDate>Thu, 15 Jul 2010 14:48:53 +0000</pubDate>
		<guid isPermaLink="false">http://blog.kiddaland.net/?p=275#comment-4330</guid>
		<description>[...] Gudjonsson released log2timeline v0.50 on June 30. This release contains a number of improvements. One of the most exciting is the [...]</description>
		<content:encoded><![CDATA[<p>[...] Gudjonsson released log2timeline v0.50 on June 30. This release contains a number of improvements. One of the most exciting is the [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on log2timeline Version 0.50 Released by Tweets that mention IR and forensic talk » log2timeline Version 0.50 Released -- Topsy.com</title>
		<link>http://blog.kiddaland.net/2010/06/log2timeline-version-0-50-released/comment-page-1/#comment-4281</link>
		<dc:creator>Tweets that mention IR and forensic talk » log2timeline Version 0.50 Released -- Topsy.com</dc:creator>
		<pubDate>Thu, 01 Jul 2010 18:42:57 +0000</pubDate>
		<guid isPermaLink="false">http://blog.kiddaland.net/?p=275#comment-4281</guid>
		<description>[...] This post was mentioned on Twitter by douglas brush, Masafumi Negishi. Masafumi Negishi said: RT log2timeline Version 0.50 Released - http://j.mp/ckVXMx [...]</description>
		<content:encoded><![CDATA[<p>[...] This post was mentioned on Twitter by douglas brush, Masafumi Negishi. Masafumi Negishi said: RT log2timeline Version 0.50 Released &#8211; <a href="http://j.mp/ckVXMx" rel="nofollow">http://j.mp/ckVXMx</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Firefox 3 History &#8211; revisited by Dyllan</title>
		<link>http://blog.kiddaland.net/2009/07/firefox-3-history-revisited/comment-page-1/#comment-4173</link>
		<dc:creator>Dyllan</dc:creator>
		<pubDate>Tue, 08 Jun 2010 10:21:43 +0000</pubDate>
		<guid isPermaLink="false">http://blog.kiddaland.net/?p=60#comment-4173</guid>
		<description>Excellent script, well done &amp; thanks.</description>
		<content:encoded><![CDATA[<p>Excellent script, well done &amp; thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Timeline Analysis 101 by Howard Patterson</title>
		<link>http://blog.kiddaland.net/2010/05/timeline-analysis-101/comment-page-1/#comment-4146</link>
		<dc:creator>Howard Patterson</dc:creator>
		<pubDate>Wed, 02 Jun 2010 01:54:57 +0000</pubDate>
		<guid isPermaLink="false">http://blog.kiddaland.net/?p=251#comment-4146</guid>
		<description>Thanks for this great intro and commentary on the timeline. I have been using the new SIFT tool, and this helps me figure out the results I&#039;m getting. I have used it on a WinXP and Vista system (both 32-bit).</description>
		<content:encoded><![CDATA[<p>Thanks for this great intro and commentary on the timeline. I have been using the new SIFT tool, and this helps me figure out the results I&#8217;m getting. I have used it on a WinXP and Vista system (both 32-bit).</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Windows Prefetch Directory by kiddi</title>
		<link>http://blog.kiddaland.net/2009/06/windows-prefetch-directory/comment-page-1/#comment-3716</link>
		<dc:creator>kiddi</dc:creator>
		<pubDate>Mon, 26 Apr 2010 12:26:37 +0000</pubDate>
		<guid isPermaLink="false">http://blog.kiddaland.net/?p=23#comment-3716</guid>
		<description>I sent you an e-mail, this should be an easy fix, just need a bit more info.</description>
		<content:encoded><![CDATA[<p>I sent you an e-mail, this should be an easy fix, just need a bit more info.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Windows Prefetch Directory by John</title>
		<link>http://blog.kiddaland.net/2009/06/windows-prefetch-directory/comment-page-1/#comment-3654</link>
		<dc:creator>John</dc:creator>
		<pubDate>Wed, 21 Apr 2010 22:36:36 +0000</pubDate>
		<guid isPermaLink="false">http://blog.kiddaland.net/?p=23#comment-3654</guid>
		<description>Thanks for the great script.  I&#039;m having trouble with the html output though... if I use the -h flag, I get an error:

$ ./read_prefetch.pl -h /tmp/report.html /mnt/analysis/WINDOWS/Prefetch/
Option h is ambiguous (help, html)

When I specify &#039;-html&#039;, the script completes dumping to stdout but not creating the html report.  Any suggestions?  I using Ubuntu 9.10.</description>
		<content:encoded><![CDATA[<p>Thanks for the great script.  I&#8217;m having trouble with the html output though&#8230; if I use the -h flag, I get an error:</p>
<p>$ ./read_prefetch.pl -h /tmp/report.html /mnt/analysis/WINDOWS/Prefetch/<br />
Option h is ambiguous (help, html)</p>
<p>When I specify &#8216;-html&#8217;, the script completes dumping to stdout but not creating the html report.  Any suggestions?  I using Ubuntu 9.10.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Timeline analysis, links and discussion by John McCash</title>
		<link>http://blog.kiddaland.net/2010/03/timeline-analysis-links-and-discussion/comment-page-1/#comment-3532</link>
		<dc:creator>John McCash</dc:creator>
		<pubDate>Tue, 13 Apr 2010 17:28:15 +0000</pubDate>
		<guid isPermaLink="false">http://blog.kiddaland.net/?p=230#comment-3532</guid>
		<description>Hey Paul - Did you ever get log2timeline working under Windows? I saw your tweet that you were giving up on Cygwin and trying Active Perl, but when I did that I made even less headway than under Cygwin. The only parts that won&#039;t compile under Cygwin are the GUI and PCAP modules. If there were some way to bypass those, frankly, I couldn&#039;t care less that they weren&#039;t there.
Thoughts?
John</description>
		<content:encoded><![CDATA[<p>Hey Paul &#8211; Did you ever get log2timeline working under Windows? I saw your tweet that you were giving up on Cygwin and trying Active Perl, but when I did that I made even less headway than under Cygwin. The only parts that won&#8217;t compile under Cygwin are the GUI and PCAP modules. If there were some way to bypass those, frankly, I couldn&#8217;t care less that they weren&#8217;t there.<br />
Thoughts?<br />
John</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on log2timeline updated by kiddi</title>
		<link>http://blog.kiddaland.net/2010/03/log2timeline-updated-2/comment-page-1/#comment-2646</link>
		<dc:creator>kiddi</dc:creator>
		<pubDate>Fri, 12 Mar 2010 18:40:05 +0000</pubDate>
		<guid isPermaLink="false">http://blog.kiddaland.net/?p=226#comment-2646</guid>
		<description>Hi,
thank you for this comment, I&#039;ve added it in my code already.  The log files that I had in my hands had the 03 notion for month that was earlier than October, so obviously they can &quot;swing&quot; both ways</description>
		<content:encoded><![CDATA[<p>Hi,<br />
thank you for this comment, I&#8217;ve added it in my code already.  The log files that I had in my hands had the 03 notion for month that was earlier than October, so obviously they can &#8220;swing&#8221; both ways</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on log2timeline updated by Paul Bobby</title>
		<link>http://blog.kiddaland.net/2010/03/log2timeline-updated-2/comment-page-1/#comment-2640</link>
		<dc:creator>Paul Bobby</dc:creator>
		<pubDate>Fri, 12 Mar 2010 15:52:53 +0000</pubDate>
		<guid isPermaLink="false">http://blog.kiddaland.net/?p=226#comment-2640</guid>
		<description>I changed line 697 to

if( $words[0] =~ m/d{1,2}/d{1,2}/d{4}/ )

the month field can be 1 or 2 characters also</description>
		<content:encoded><![CDATA[<p>I changed line 697 to</p>
<p>if( $words[0] =~ m/d{1,2}/d{1,2}/d{4}/ )</p>
<p>the month field can be 1 or 2 characters also</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on log2timeline updated by Paul Bobby</title>
		<link>http://blog.kiddaland.net/2010/03/log2timeline-updated-2/comment-page-1/#comment-2603</link>
		<dc:creator>Paul Bobby</dc:creator>
		<pubDate>Thu, 11 Mar 2010 20:07:27 +0000</pubDate>
		<guid isPermaLink="false">http://blog.kiddaland.net/?p=226#comment-2603</guid>
		<description>When running log2timeline with the mcafee option I get the following:

pbobby@ubuntu:~/Documents/log2timeline$ log2timeline -z US/Eastern -f mcafee ./fred/AccessProtectionLog.txt 
Start processing file/dir [./fred/AccessProtectionLog.txt] ...
Loading output file: mactime
Starting to parse file using format: [mcafee] 
This is a plugin of unkown origin.  It parses a log file and contains no requirements or 
any other relevant options or possibilites, use with care...
------------------------

File ./fred/AccessProtectionLog.txt is not of the right format.
Error given from format file: The date field is not correctly formed(10/4/2009)

------------------------


Usage:
    log2timeline [OPTIONS] -f FORMAT LOG_FILE/LOG_DIR [--] [FORMAT FILE
    OPTIONS]

pbobby@ubuntu:~/Documents/log2timeline$</description>
		<content:encoded><![CDATA[<p>When running log2timeline with the mcafee option I get the following:</p>
<p>pbobby@ubuntu:~/Documents/log2timeline$ log2timeline -z US/Eastern -f mcafee ./fred/AccessProtectionLog.txt<br />
Start processing file/dir [./fred/AccessProtectionLog.txt] &#8230;<br />
Loading output file: mactime<br />
Starting to parse file using format: [mcafee]<br />
This is a plugin of unkown origin.  It parses a log file and contains no requirements or<br />
any other relevant options or possibilites, use with care&#8230;<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p>File ./fred/AccessProtectionLog.txt is not of the right format.<br />
Error given from format file: The date field is not correctly formed(10/4/2009)</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p>Usage:<br />
    log2timeline [OPTIONS] -f FORMAT LOG_FILE/LOG_DIR [--] [FORMAT FILE<br />
    OPTIONS]</p>
<p>pbobby@ubuntu:~/Documents/log2timeline$</p>
]]></content:encoded>
	</item>
</channel>
</rss>
