We received a request for an article for pdgmail which is a Python script that analyzes Windows and Linux browser process dumps where the browser had Gmail open. I was able to test on 32-bit Windows 7, 64-bit Ubuntu 10.04 LTS, and 32-bit Ubuntu 10.04 LTS. Unfortunately the methods I was using did not work properly on the 64-bit Ubuntu however it worked perfectly on both 32-bit operating systems I tested. Below I describe how pdgmail can be used to dump Firefox process memory using Process Dumper on Backtrack Linux which is technically Ubuntu 10.04 LTS.
Tags: backtrack, dump, firefox, forensics, gmail, memory, pdgmail, pdgmail.py, process dumper, python, ram forensics tools, ubuntu
Archive for April 2nd, 2012 |
|
|
||||









Entries (RSS)