Vinetto for Linux

Vinetto is a forensics tool to examine Thumbs.db files for Linux.
Download

Vinetto for Linux Ranking & Summary

Advertisement

  • Rating:
  • License:
  • Freeware
  • Publisher Name:
  • Michel Roukine
  • Publisher web site:
  • Operating Systems:
  • Linux
  • File Size:
  • 15KB

Vinetto for Linux Tags


Vinetto for Linux Description

1 - Context : The Windows systems (98, ME, 2000, XP and 2003 Server) can store thumbnails and metadata of the picture files contained in the directories of its FAT32 or NTFS filesystems. The thumbnails and associated metadata are stored in Thumbs.db files. The Thumbs.db files are undocumented OLE structured files. Once a picture file has been deleted from the FileSystem, the related thumbnail and associated metada remain stored in the Thumbs.db file. So, the data contained in those thumbs.db files are an helpful source of information for the forensics investigator. 2 - What the software is intended to do : Vinetto extracts the thumbnails and associated metadata from the Thumbs.db files. Moreover it runs according to three modes: > elementary mode : in this mode vinetto extracts thumbnails and metadata from a chosen Thumbs.db file. > directory mode : in this mode vinetto checks for consistency between the content of the directory and the related Thumbs.db file i.e. it will report the thumbnails that are not associated to a file into the directory. > filesystem mode : in this mode vinetto will process the whole FAT or NTFS Partition. 3 - What purpose it will serve : Vinetto will help *nix-based forensics investigators to : > easily preview thumbnails of deleted pictures on Windows systems, > obtain informations (dates, path, ...) about those deleted images. 4 - Misc. : Vinetto is intended to be integrated into forensics liveCD like FCCU GNU/Linux Forensic Boot CD.


Vinetto for Linux Related Software