LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie
User Name
Password
Linux - Newbie This Linux forum is for members that are new to Linux.
Just starting out and have a question? If it is not in the man pages or the how-to's this is the place!

Notices


Reply
  Search this Thread
Old 05-01-2019, 08:13 AM   #1
shaunofi
LQ Newbie
 
Registered: May 2019
Posts: 3

Rep: Reputation: Disabled
Scalpel Help Needed Urgently


Hi All

My data center was hit with ransom ware. I am hoping you can help me. I am using the scalpel software to recover. I need help adding the file extensions to the scalpel.conf file. The extensions are .sna .hsh .sn1

Any advice will be appreciated
 
Old 05-01-2019, 08:18 AM   #2
TB0ne
LQ Guru
 
Registered: Jul 2003
Location: Birmingham, Alabama
Distribution: SuSE, RedHat, Slack,CentOS
Posts: 26,634

Rep: Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965
Quote:
Originally Posted by shaunofi View Post
Hi All
My data center was hit with ransom ware. I am hoping you can help me. I am using the scalpel software to recover. I need help adding the file extensions to the scalpel.conf file. The extensions are .sna .hsh .sn1

Any advice will be appreciated
There is nothing 'urgent' about this for anyone here but you. We volunteer our time to help folks, so asking for/expecting 'urgent' help is fairly rude. And you give us ZERO details; what version/distro of Linux??

Got hit with ransomware? Then you have options:Personally, I'd trust **ZERO** of what you're trying to recover. Restore from a known clean backup and move forward.
 
Old 05-01-2019, 08:22 AM   #3
shaunofi
LQ Newbie
 
Registered: May 2019
Posts: 3

Original Poster
Rep: Reputation: Disabled
My apologies!

I am new to Linux and extremely stressed trying to find a solution
 
Old 05-01-2019, 08:28 AM   #4
TB0ne
LQ Guru
 
Registered: Jul 2003
Location: Birmingham, Alabama
Distribution: SuSE, RedHat, Slack,CentOS
Posts: 26,634

Rep: Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965
Quote:
Originally Posted by shaunofi View Post
My apologies!
I am new to Linux and extremely stressed trying to find a solution
Again: without details there is zero we can help you with. There are many how-to guides for using scalpel, but as stated, if you were actually hit with ransomware, I'd not trust ANY of your data, period, at all.

Restore from clean backups from well before the incident. That's what they're for.
 
Old 05-01-2019, 09:12 AM   #5
shaunofi
LQ Newbie
 
Registered: May 2019
Posts: 3

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by TB0ne View Post
Again: without details there is zero we can help you with. There are many how-to guides for using scalpel, but as stated, if you were actually hit with ransomware, I'd not trust ANY of your data, period, at all.

Restore from clean backups from well before the incident. That's what they're for.
Unfortunately the backups were destroyed as well. I managed to install Scalpel. The Scalpel.conf file needs to first be configured for the file extension I want to recover.
I added in the file extension. It recovers folders but not the files. I am assuming I added the extensions incorrectly
 
Old 05-01-2019, 09:20 AM   #6
TB0ne
LQ Guru
 
Registered: Jul 2003
Location: Birmingham, Alabama
Distribution: SuSE, RedHat, Slack,CentOS
Posts: 26,634

Rep: Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965
Quote:
Originally Posted by shaunofi View Post
Unfortunately the backups were destroyed as well. I managed to install Scalpel. The Scalpel.conf file needs to first be configured for the file extension I want to recover. I added in the file extension. It recovers folders but not the files. I am assuming I added the extensions incorrectly
..and back to, AGAIN, not knowing ANYTHING past ransomware and scalpel. You **STILL** aren't saying what version/distro of Linux, how you installed Scalpel, or what you've done/tried. Doesn't have anything to do with Linux to describe a problem...you wouldn't call a mechanic and say "Help! My car won't start but I put fuel in!!" would you? Wouldn't you say what kind of car, fuel, etc.??? This isn't different.

Sorry, but unless you can provide relevant details, there is absolutely NOTHING we can help you with. Since you don't have backups, there may be nothing else to do but to start fresh. How, exactly, were your backups destroyed?? Weren't they on a different disk/media??? If not, you do realize that you didn't HAVE a backup, right??
 
Old 05-01-2019, 03:14 PM   #7
ondoho
LQ Addict
 
Registered: Dec 2013
Posts: 19,872
Blog Entries: 12

Rep: Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053
the first rule when recovering lost data is to NOT use that hard drive anymore!
need to boot live!
i hope you didn't install that software on the same hard drive...
 
Old 05-01-2019, 05:11 PM   #8
ChuangTzu
Senior Member
 
Registered: May 2015
Location: Where ever needed
Distribution: Slackware/Salix while testing others
Posts: 1,718

Rep: Reputation: 1857Reputation: 1857Reputation: 1857Reputation: 1857Reputation: 1857Reputation: 1857Reputation: 1857Reputation: 1857Reputation: 1857Reputation: 1857Reputation: 1857
https://www.linuxquestions.org/linux...Ask_a_Question

How did you confirm the ransomware and not someone just yanking your digital chain?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
need help using Scalpel to recover files newbiesforever Linux - Software 2 02-13-2013 09:55 PM
LXer: Recover Your Deleted Files In Linux using Scalpel Utility LXer Syndicated Linux News 0 12-26-2011 05:41 PM
LXer: Recover Your Deleted Files In Linux using Scalpel Utility LXer Syndicated Linux News 0 07-29-2011 04:41 PM
scalpel carver and skipping blocks mpapet Linux - General 4 10-02-2010 08:14 AM
LXer: AbiWord: A Scalpel, Not a Chain Saw LXer Syndicated Linux News 0 07-16-2008 02:11 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie

All times are GMT -5. The time now is 12:32 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration