LinuxQuestions.org
LinuxAnswers - the LQ Linux tutorial section.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - General
User Name
Password
Linux - General This Linux forum is for general Linux questions and discussion.
If it is Linux Related and doesn't seem to fit in any other forum then this is the place.

Notices

Reply
 
Search this Thread
Old 10-04-2005, 06:46 PM   #1
newlinuxnewbie
Member
 
Registered: Sep 2005
Posts: 114

Rep: Reputation: 15
200GB of files Deleted - How to Recover?


I just lost 200GB of data due to deletion by a hacker. Are there any possibility of recovering the files? I found out it is using ext3.

Please help me.

Thanks!!

Last edited by newlinuxnewbie; 10-04-2005 at 06:52 PM.
 
Old 10-04-2005, 07:09 PM   #2
anomie
Senior Member
 
Registered: Nov 2004
Location: Texas
Distribution: RHEL, Scientific Linux, Debian, Fedora, Lubuntu, FreeBSD
Posts: 3,930
Blog Entries: 5

Rep: Reputation: Disabled
First - not to make light of your serious situation - but a cracker deleted your files. A hacker did not.

The first thing you need to do is turn the pc off - stop using it. The recovery process will probably have to happen with knoppix or another live cd. While you leave the computer running, you are overwriting the drive space where the unlinked, "removed" files are.

Have a look at the Coroner's Toolkit: http://www.porcupine.org/forensics/tct.html

The tools you may be able to use are unrm and lazarus. I have not used either but I've read about this toolkit.

Unfortunately, with 200GB of data I have serious doubts that you will be able to recover most of it.
 
Old 10-04-2005, 07:40 PM   #3
unSpawn
Moderator
 
Registered: May 2001
Posts: 27,319
Blog Entries: 54

Rep: Reputation: 2860Reputation: 2860Reputation: 2860Reputation: 2860Reputation: 2860Reputation: 2860Reputation: 2860Reputation: 2860Reputation: 2860Reputation: 2860Reputation: 2860
Second thing after shutting down is securing the state of the drive(s). Bring the box up again with KNOPPIX, FIRE or PSK, mount the partitions read-only and make a backup to another box or put the HD's in another box to clone them there.

After that you have to consider how much this data is worth because learning forensics tools like TCT, Sleuthkit and Autopsy *will cost you time* + the longer the period between unlinking and fixating the data the less chance you stand. You should read the docs and then practice on another box with trivial data. Do this at least a few times so you learn from mistakes etc, etc. When you're ready to work with your backups (only work on the backups, never the original data in case it all fscks up), make sure you set up your workstation with plenty of spare storage.

Good luck.
 
Old 10-04-2005, 08:20 PM   #4
newlinuxnewbie
Member
 
Registered: Sep 2005
Posts: 114

Original Poster
Rep: Reputation: 15
I was told that it is impossible to recover deleted files from partitions using the ext3 file system. These tools can help me recover the files?

Yes, a cracker deleted the files, I am trying to find out how how he got in and hopefully get enough information to prosecute him.
 
Old 10-05-2005, 12:03 PM   #5
Agrouf
Senior Member
 
Registered: Sep 2005
Location: France
Distribution: LFS
Posts: 1,591

Rep: Reputation: 79
In some cases, testdisk can help.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
recover deleted windows files from linux(help) rkrishna Linux - General 2 06-22-2005 11:32 AM
how to recover deleted files sibtay Linux - Software 13 01-22-2005 08:09 PM
Recover deleted files on CDUDF (Direct CD) Vincent_Vega Linux - General 2 12-29-2004 11:08 PM
Recover deleted files? subaruwrx Linux - Newbie 8 06-04-2004 08:47 AM
Recover deleted files markdw Linux - General 1 12-07-2001 04:08 PM


All times are GMT -5. The time now is 08:13 PM.

Main Menu
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration