summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorDaniel Black <dragonheart@gentoo.org>2005-01-26 02:44:04 +0000
committerDaniel Black <dragonheart@gentoo.org>2005-01-26 02:44:04 +0000
commit84e4988066e93509c742f25ef72f8f850c4c1d3c (patch)
tree8330ef588d34894be1483cf9edb6ff3cf43fbadb /app-forensics/mac-robber
parentMarked ~ppc for bug #77759. (diff)
downloadgentoo-2-84e4988066e93509c742f25ef72f8f850c4c1d3c.tar.gz
gentoo-2-84e4988066e93509c742f25ef72f8f850c4c1d3c.tar.bz2
gentoo-2-84e4988066e93509c742f25ef72f8f850c4c1d3c.zip
Initial import.
(Portage version: 2.0.51-r15)
Diffstat (limited to 'app-forensics/mac-robber')
-rw-r--r--app-forensics/mac-robber/ChangeLog8
-rw-r--r--app-forensics/mac-robber/Manifest4
-rw-r--r--app-forensics/mac-robber/files/digest-mac-robber-1.001
-rw-r--r--app-forensics/mac-robber/mac-robber-1.00.ebuild31
-rw-r--r--app-forensics/mac-robber/metadata.xml24
5 files changed, 68 insertions, 0 deletions
diff --git a/app-forensics/mac-robber/ChangeLog b/app-forensics/mac-robber/ChangeLog
new file mode 100644
index 000000000000..bee57432a5d1
--- /dev/null
+++ b/app-forensics/mac-robber/ChangeLog
@@ -0,0 +1,8 @@
+# ChangeLog for app-forensics/mac-robber
+# Copyright 1999-2005 Gentoo Foundation; Distributed under the GPL v2
+# $Header: /var/cvsroot/gentoo-x86/app-forensics/mac-robber/ChangeLog,v 1.1 2005/01/26 02:44:04 dragonheart Exp $
+
+ 26 Jan 2005; Daniel Black <dragonheart@gentoo.org>
+ +mac-robber-1.00.ebuild, +metadata.xml:
+ Initial import. Suggested by Michael Zanetta <mzanetta@telsys.ch>.
+
diff --git a/app-forensics/mac-robber/Manifest b/app-forensics/mac-robber/Manifest
new file mode 100644
index 000000000000..8baab25c3702
--- /dev/null
+++ b/app-forensics/mac-robber/Manifest
@@ -0,0 +1,4 @@
+MD5 719831ae04815275ae93ec42c69fca89 mac-robber-1.00.ebuild 723
+MD5 1e9937a862e19cdf3f8b0838c48c2ce5 metadata.xml 1434
+MD5 ed366bd36589891555de26927e783b64 ChangeLog 291
+MD5 df98bdff9227fef4cff867355797b655 files/digest-mac-robber-1.00 66
diff --git a/app-forensics/mac-robber/files/digest-mac-robber-1.00 b/app-forensics/mac-robber/files/digest-mac-robber-1.00
new file mode 100644
index 000000000000..4eb547f91a21
--- /dev/null
+++ b/app-forensics/mac-robber/files/digest-mac-robber-1.00
@@ -0,0 +1 @@
+MD5 902afd8e6121e153bbc8cb93013667fd mac-robber-1.00.tar.gz 11483
diff --git a/app-forensics/mac-robber/mac-robber-1.00.ebuild b/app-forensics/mac-robber/mac-robber-1.00.ebuild
new file mode 100644
index 000000000000..d24b835bf24d
--- /dev/null
+++ b/app-forensics/mac-robber/mac-robber-1.00.ebuild
@@ -0,0 +1,31 @@
+# Copyright 1999-2005 Gentoo Foundation
+# Distributed under the terms of the GNU General Public License v2
+# $Header: /var/cvsroot/gentoo-x86/app-forensics/mac-robber/mac-robber-1.00.ebuild,v 1.1 2005/01/26 02:44:04 dragonheart Exp $
+
+inherit toolchain-funcs
+
+DESCRIPTION="mac-robber is a digital forensics and incident response tool that collects data"
+HOMEPAGE="http://www.sleuthkit.org/mac-robber/index.php"
+SRC_URI="mirror://sourceforge/${PN}/${P}.tar.gz"
+
+LICENSE="GPL-2"
+SLOT="0"
+KEYWORDS="x86"
+IUSE=""
+
+DEPEND="virtual/libc"
+
+
+src_compile() {
+ emake CC="$(tc-getCC)" GCC_OPT="${CFLAGS}" \
+ || die "make failed"
+}
+
+src_test() {
+ ./mac-robber -V || die "test failed"
+}
+
+src_install() {
+ dobin mac-robber
+ dodoc README
+}
diff --git a/app-forensics/mac-robber/metadata.xml b/app-forensics/mac-robber/metadata.xml
new file mode 100644
index 000000000000..39c63700da50
--- /dev/null
+++ b/app-forensics/mac-robber/metadata.xml
@@ -0,0 +1,24 @@
+<?xml version="1.0" encoding="UTF-8"?>
+<!DOCTYPE pkgmetadata SYSTEM "http://www.gentoo.org/dtd/metadata.dtd">
+<pkgmetadata>
+<herd>forensics</herd>
+<maintainer>
+ <email>forensics@gentoo.org</email>
+ <name>Forensics Herd</name>
+</maintainer>
+<longdescription>
+mac-robber is a digital forensics and incident response tool that collects data from allocated files in a mounted file system.
+The data can be used by the mactime tool in The Sleuth Kit to make a timeline of file activity. The mac-robber tool is based on
+the grave-robber tool from TCT and is written in C instead of Perl.
+
+mac-robber requires that the file system be mounted by the operating system, unlike the tools in The Sleuth Kit that process the
+file system themselves. Therefore, mac-robber will not collect data from deleted files or files that have been hidden by
+rootkits. mac-robber will also modify the Access times on directories that are mounted with write permissions.
+
+
+"What is mac-robber good for then", you ask? mac-robber is useful when dealing with a file system that is not supported by The
+Sleuth Kit or other forensic tools. mac-robber is very basic C and should compile on any UNIX system. Therefore, you can run
+mac-robber on an obscure, suspect UNIX file system that has been mounted read-only on a trusted system. I have also used
+mac-robber during investigations of common UNIX systems such as AIX.
+</longdescription>
+</pkgmetadata>