next up previous
Next: Putting names on inodes Up: The Challenge Previous: The Challenge

List deleted files

Since the goal of this challenge is to recover a deleted rootkit in the / partition, we start by doing this.

The first thing we do is to run ils on the partition image in order to list all the deleted files in this partition:


ils -r honeynet/honeypot.hda8.dd

We present the output in the next table. Note that the field st_alloc has been removed from the table; all its entries were f. The field st_nlink has also been removed from the table; all its entries were 0.

st_ino st_uid st_gid st_mtime st_atime st_ctime st_dtime st_mode st_size st_block0 st_block1
23 0 0 984706608 984707090 984707105 984707105 100644 520333 307 308
2038 1031 100 984707105 984707105 984707105 984707169 40755 0 8481 0
2039 0 0 1013173693 984707090 984707105 984707105 100755 611931 8482 8483
2040 0 0 983201398 984707090 984707105 984707105 100644 1 9084 0
2041 0 0 983588917 984707105 984707105 984707105 100700 3713 9085 9086
2042 0 0 984707105 984707105 984707105 984707105 100644 796 9124 0
2043 0 0 936892631 984707090 984707105 984707105 100755 1345 9096 9097
2044 0 0 980608292 984707103 984707105 984707105 100644 3278 9098 9099
2045 0 0 983201320 984707103 984707105 984707105 100755 79 9102 0
2046 0 0 980608304 984707103 984707105 984707105 100644 11407 9103 9104
2047 0 0 983200975 984707102 984707103 984707103 100755 4060 9115 9116
2048 0 0 972242984 984707090 984707105 984707105 100644 880 9119 0
2049 0 0 972242984 984707103 984707103 984707103 100600 540 9120 0
2050 0 0 972242984 984707090 984707105 984707105 100644 344 9121 0
2051 0 0 972242984 984707103 984707103 984707103 100600 512 9122 0
2052 0 0 983201391 984707090 984707105 984707105 100644 688 9123 0
2053 0 0 983200979 984707102 984707103 984707103 100700 8268 9124 9125
2054 0 0 983200990 984707105 984707105 984707105 100755 4620 9133 9134
2058 0 0 983201035 984707102 984707102 984707102 100755 53588 9229 9230
2059 0 0 983201043 984707102 984707103 984707103 100700 75 9283 0
2060 0 0 983588712 984707103 984707103 984707103 100644 708 9284 0
2061 0 0 983198764 984707103 984707103 984707103 100755 632066 9285 9286
8097 0 0 984736992 984736921 984736992 984736992 40700 0 33062 0
8100 0 0 984736992 984736992 984736992 984736992 100644 16329 33063 33064
12107 0 0 984655177 984655177 984655225 984655225 120777 16 1764699694 779381102
16110 0 0 949962039 984655225 984655225 984655225 100644 239 65860 0
20883 0 0 984655177 984655177 984655225 984655225 120777 16 1764699694 779381102
22103 0 0 984754122 984754122 984754122 984754122 100600 0 0 0
22104 0 0 984754122 984754122 984754122 984754122 100600 0 0 0
22105 0 0 984754122 984754122 984754122 984754122 100644 0 0 0
22106 0 0 984754076 984754076 984754076 984754076 100600 0 0 0
22107 0 0 984754076 984754076 984754076 984754076 100600 0 0 0
22108 0 0 984754076 984754076 984754076 984754076 100644 0 0 0
28172 0 0 984655177 984655177 984655225 984655225 120777 16 1764699694 779381102
30188 0 0 952425102 984677103 984707102 984707102 100755 66736 126628 126629
30191 0 0 952452206 984677352 984707102 984707102 100555 60080 126695 126696
48284 0 0 952425102 984677122 984707102 984707102 100755 42736 199330 199331
56231 0 0 984655056 984655056 984655056 984655056 100644 33135 229685 229686

This table is a bit hard to read, but will still be helpfull later to know which files were the files used by the blackhat.


next up previous
Next: Putting names on inodes Up: The Challenge Previous: The Challenge
Guillaume Filion
2001-05-21