summaryrefslogtreecommitdiff
path: root/app-forensics/mac-robber
diff options
context:
space:
mode:
authorV3n3RiX <venerix@redcorelinux.org>2017-10-09 18:53:29 +0100
committerV3n3RiX <venerix@redcorelinux.org>2017-10-09 18:53:29 +0100
commit4f2d7949f03e1c198bc888f2d05f421d35c57e21 (patch)
treeba5f07bf3f9d22d82e54a462313f5d244036c768 /app-forensics/mac-robber
reinit the tree, so we can have metadata
Diffstat (limited to 'app-forensics/mac-robber')
-rw-r--r--app-forensics/mac-robber/Manifest5
-rw-r--r--app-forensics/mac-robber/mac-robber-1.02.ebuild28
-rw-r--r--app-forensics/mac-robber/metadata.xml23
3 files changed, 56 insertions, 0 deletions
diff --git a/app-forensics/mac-robber/Manifest b/app-forensics/mac-robber/Manifest
new file mode 100644
index 000000000000..8b9f7cdc7b9c
--- /dev/null
+++ b/app-forensics/mac-robber/Manifest
@@ -0,0 +1,5 @@
+DIST mac-robber-1.02.tar.gz 11708 SHA256 5895d332ec8d87e15f21441c61545b7f68830a2ee2c967d381773bd08504806d SHA512 5330f766eb08aa766ca3f430684e0a40ecf29b7230a582c30a36bbaaa481d52c2a8519fa04e82762f09259ada9e77466c1430aebdff22615a511d519916d54a7 WHIRLPOOL e289325435b654c67874888d9cf08b07a2bc412610ffefaaf4fbd90da0060f42f131c215479463cc7f004a3d2d27af5fdbbbf05ac8d7f67f3fc3396874713c99
+EBUILD mac-robber-1.02.ebuild 603 SHA256 8ecf238498063a176e67e70267cebf73ad3a562427b411c8adbc8d2b99e5360d SHA512 4f75912d8df1d080cd1aa2b48f85b440709e80681223ea67dcd49b5112f6bad8fbaa128094f5f314b7232679e782c94126a807f6578f617fca486ea07141ee3b WHIRLPOOL 4792f561c20e223c97475aef071fd4ecd695079c05bf3587e7cdbf99be05e4e78ea18b482f51906599cf726e10e9c69c787babf2e55bd63377540bf072000ea5
+MISC ChangeLog 2439 SHA256 6691cebefa0e8f125f28ccca5a332d0ea39a435b088785379b31cdf1b1df3516 SHA512 d891335166a6a2d3a6b19a9ea9028a52b770b0b4a3fb3cd258b5f043f5ee82a6eaa2f6c86d18f00b069149a6e456568bc10549e30edd1a38b8dbf5f8a4c9dc23 WHIRLPOOL 05d4e68d290b997cd87692a951914be9d83555b77b17739cdf20d31f5e9713fe3fc351c3926172acf116fd10b607b1080a53742dae3897fee3d9461516c881a1
+MISC ChangeLog-2015 1352 SHA256 6635234a110c00cea03f455e31c06c9737d4d705bb53e5a794609a842d34feb8 SHA512 7d6ddb285f03aa9afe4aa243d20b212b9df6941272c167b48159f579085761ec8143c5d55cedc1b522dabbb2e94c938e14bec36c6fc681de09bd5a7186828f8a WHIRLPOOL a7f350ead190bda1d1db37b92793667c6addcd5c54482ae4ae43b8d0b75ab5ce6c42177a757218e614a33e44e80f36f60829dfae248f831f26eb6ea351bcd0cc
+MISC metadata.xml 1423 SHA256 8a59fea5dfa16fb42baa6897bdd2ed167a63fa5059b1c4be0d3f1c78251ed398 SHA512 3af947bce0415529c1e0af7d8362db0a7ab53d685294c6dba69868acdf920b8199a19dbd0a9272c12bd97e6aaac1da78a5a537064793859858727286e8270dfb WHIRLPOOL a17ab14c5ce0918bfbfb353eb47638b2efb57c08e0a2bb5e87a8fc1e11133d185073c6407a80546fbc3bd444525fad5602694c49b7701690dd307d0d01ff41ad
diff --git a/app-forensics/mac-robber/mac-robber-1.02.ebuild b/app-forensics/mac-robber/mac-robber-1.02.ebuild
new file mode 100644
index 000000000000..90645ef09d5d
--- /dev/null
+++ b/app-forensics/mac-robber/mac-robber-1.02.ebuild
@@ -0,0 +1,28 @@
+# Copyright 1999-2012 Gentoo Foundation
+# Distributed under the terms of the GNU General Public License v2
+
+EAPI=4
+
+inherit toolchain-funcs
+
+DESCRIPTION="mac-robber is a digital forensics and incident response tool that collects data"
+HOMEPAGE="http://www.sleuthkit.org/mac-robber/index.php"
+SRC_URI="mirror://sourceforge/${PN}/${P}.tar.gz"
+
+LICENSE="GPL-2"
+SLOT="0"
+KEYWORDS="~amd64 ~ppc x86"
+IUSE=""
+
+src_prepare() {
+ sed -i -e 's:$(GCC_CFLAGS):\0 $(LDFLAGS):' Makefile || die
+}
+
+src_compile() {
+ emake CC="$(tc-getCC)" GCC_OPT="${CFLAGS}"
+}
+
+src_install() {
+ dobin mac-robber
+ dodoc CHANGES README
+}
diff --git a/app-forensics/mac-robber/metadata.xml b/app-forensics/mac-robber/metadata.xml
new file mode 100644
index 000000000000..2ce6a4b5d677
--- /dev/null
+++ b/app-forensics/mac-robber/metadata.xml
@@ -0,0 +1,23 @@
+<?xml version="1.0" encoding="UTF-8"?>
+<!DOCTYPE pkgmetadata SYSTEM "http://www.gentoo.org/dtd/metadata.dtd">
+<pkgmetadata>
+ <!-- maintainer-needed -->
+ <longdescription>
+mac-robber is a digital forensics and incident response tool that collects data from allocated files in a mounted file system.
+The data can be used by the mactime tool in The Sleuth Kit to make a timeline of file activity. The mac-robber tool is based on
+the grave-robber tool from TCT and is written in C instead of Perl.
+
+mac-robber requires that the file system be mounted by the operating system, unlike the tools in The Sleuth Kit that process the
+file system themselves. Therefore, mac-robber will not collect data from deleted files or files that have been hidden by
+rootkits. mac-robber will also modify the Access times on directories that are mounted with write permissions.
+
+
+"What is mac-robber good for then", you ask? mac-robber is useful when dealing with a file system that is not supported by The
+Sleuth Kit or other forensic tools. mac-robber is very basic C and should compile on any UNIX system. Therefore, you can run
+mac-robber on an obscure, suspect UNIX file system that has been mounted read-only on a trusted system. I have also used
+mac-robber during investigations of common UNIX systems such as AIX.
+</longdescription>
+ <upstream>
+ <remote-id type="sourceforge">mac-robber</remote-id>
+ </upstream>
+</pkgmetadata>