Download your favorite Linux distribution at LQ ISO.
Go Back > Forums > Linux Forums > Linux - General
User Name
Linux - General This Linux forum is for general Linux questions and discussion.
If it is Linux Related and doesn't seem to fit in any other forum then this is the place.


  Search this Thread
Old 10-04-2005, 07:46 PM   #1
Registered: Sep 2005
Posts: 114

Rep: Reputation: 15
200GB of files Deleted - How to Recover?

I just lost 200GB of data due to deletion by a hacker. Are there any possibility of recovering the files? I found out it is using ext3.

Please help me.


Last edited by newlinuxnewbie; 10-04-2005 at 07:52 PM.
Old 10-04-2005, 08:09 PM   #2
Senior Member
Registered: Nov 2004
Location: Texas
Distribution: RHEL, Scientific Linux, Debian, Fedora
Posts: 3,935
Blog Entries: 5

Rep: Reputation: Disabled
First - not to make light of your serious situation - but a cracker deleted your files. A hacker did not.

The first thing you need to do is turn the pc off - stop using it. The recovery process will probably have to happen with knoppix or another live cd. While you leave the computer running, you are overwriting the drive space where the unlinked, "removed" files are.

Have a look at the Coroner's Toolkit:

The tools you may be able to use are unrm and lazarus. I have not used either but I've read about this toolkit.

Unfortunately, with 200GB of data I have serious doubts that you will be able to recover most of it.
Old 10-04-2005, 08:40 PM   #3
Registered: May 2001
Posts: 29,361
Blog Entries: 55

Rep: Reputation: 3547Reputation: 3547Reputation: 3547Reputation: 3547Reputation: 3547Reputation: 3547Reputation: 3547Reputation: 3547Reputation: 3547Reputation: 3547Reputation: 3547
Second thing after shutting down is securing the state of the drive(s). Bring the box up again with KNOPPIX, FIRE or PSK, mount the partitions read-only and make a backup to another box or put the HD's in another box to clone them there.

After that you have to consider how much this data is worth because learning forensics tools like TCT, Sleuthkit and Autopsy *will cost you time* + the longer the period between unlinking and fixating the data the less chance you stand. You should read the docs and then practice on another box with trivial data. Do this at least a few times so you learn from mistakes etc, etc. When you're ready to work with your backups (only work on the backups, never the original data in case it all fscks up), make sure you set up your workstation with plenty of spare storage.

Good luck.
Old 10-04-2005, 09:20 PM   #4
Registered: Sep 2005
Posts: 114

Original Poster
Rep: Reputation: 15
I was told that it is impossible to recover deleted files from partitions using the ext3 file system. These tools can help me recover the files?

Yes, a cracker deleted the files, I am trying to find out how how he got in and hopefully get enough information to prosecute him.
Old 10-05-2005, 01:03 PM   #5
Senior Member
Registered: Sep 2005
Location: France
Distribution: LFS
Posts: 1,591

Rep: Reputation: 79
In some cases, testdisk can help.


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
recover deleted windows files from linux(help) rkrishna Linux - General 2 06-22-2005 12:32 PM
how to recover deleted files sibtay Linux - Software 13 01-22-2005 09:09 PM
Recover deleted files on CDUDF (Direct CD) Vincent_Vega Linux - General 2 12-30-2004 12:08 AM
Recover deleted files? subaruwrx Linux - Newbie 8 06-04-2004 09:47 AM
Recover deleted files markdw Linux - General 1 12-07-2001 05:08 PM > Forums > Linux Forums > Linux - General

All times are GMT -5. The time now is 08:47 AM.

Main Menu
Write for LQ is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration