<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Windd 1.3 Final! (x86 and x64)</title>
	<atom:link href="http://www.msuiche.net/2009/10/11/windd-1-3-final-x86-and-x64/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.msuiche.net/2009/10/11/windd-1-3-final-x86-and-x64/</link>
	<description>Happiness only real when shared.</description>
	<lastBuildDate>Sun, 07 Mar 2010 03:10:11 +0100</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.3</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Scotty Keniry</title>
		<link>http://www.msuiche.net/2009/10/11/windd-1-3-final-x86-and-x64/comment-page-1/#comment-24377</link>
		<dc:creator>Scotty Keniry</dc:creator>
		<pubDate>Sun, 07 Mar 2010 03:10:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.msuiche.net/?p=335#comment-24377</guid>
		<description>I really like the fresh perpective you did on the issue. Really was not expecting that when I started off studying. Your concepts were easy to understand that I wondered why I never looked at it before. Glad to know that there&#039;s an individual out there that definitely understands what he&#039;s discussing. Great job</description>
		<content:encoded><![CDATA[<p>I really like the fresh perpective you did on the issue. Really was not expecting that when I started off studying. Your concepts were easy to understand that I wondered why I never looked at it before. Glad to know that there&#8217;s an individual out there that definitely understands what he&#8217;s discussing. Great job</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matthieu Suiche</title>
		<link>http://www.msuiche.net/2009/10/11/windd-1-3-final-x86-and-x64/comment-page-1/#comment-23857</link>
		<dc:creator>Matthieu Suiche</dc:creator>
		<pubDate>Fri, 05 Feb 2010 03:23:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.msuiche.net/?p=335#comment-23857</guid>
		<description>Look in the registry for &quot;win32dd&quot; delete the key -- the associated
path should be the wrong path.

In fact this version is not scriptable.

One you try to win32dd.exe like
&gt; path/win32dd.exe /f pouet.bin
you will get this error every time.

You have to run it from the current directory everytime
&gt; win32dd.exe /f pouet.bin</description>
		<content:encoded><![CDATA[<p>Look in the registry for &#8220;win32dd&#8221; delete the key &#8212; the associated<br />
path should be the wrong path.</p>
<p>In fact this version is not scriptable.</p>
<p>One you try to win32dd.exe like<br />
> path/win32dd.exe /f pouet.bin<br />
you will get this error every time.</p>
<p>You have to run it from the current directory everytime<br />
> win32dd.exe /f pouet.bin</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MrPockets</title>
		<link>http://www.msuiche.net/2009/10/11/windd-1-3-final-x86-and-x64/comment-page-1/#comment-23829</link>
		<dc:creator>MrPockets</dc:creator>
		<pubDate>Wed, 03 Feb 2010 20:34:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.msuiche.net/?p=335#comment-23829</guid>
		<description>I&#039;ve also run into the 

Error: InstallDriver Cannot start service (Err=0×00000002).
-&gt; Error: Cannot open \\.\win32dd.  

 I&#039;ve seen it on 32 bit installs of XP SP2 (2 gigs RAM) and SP3 (8 gigs, 32bit system == 4 available). I seem to run into it after killing or interrupting the imaging process. Haven&#039;t found a way to fix / repair it yet.</description>
		<content:encoded><![CDATA[<p>I&#8217;ve also run into the </p>
<p>Error: InstallDriver Cannot start service (Err=0×00000002).<br />
-&gt; Error: Cannot open \\.\win32dd.  </p>
<p> I&#8217;ve seen it on 32 bit installs of XP SP2 (2 gigs RAM) and SP3 (8 gigs, 32bit system == 4 available). I seem to run into it after killing or interrupting the imaging process. Haven&#8217;t found a way to fix / repair it yet.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: lacie</title>
		<link>http://www.msuiche.net/2009/10/11/windd-1-3-final-x86-and-x64/comment-page-1/#comment-22574</link>
		<dc:creator>lacie</dc:creator>
		<pubDate>Wed, 16 Dec 2009 20:59:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.msuiche.net/?p=335#comment-22574</guid>
		<description>I&#039;m also seeing crashes on x86 xp sp3:

Error: InstallDriver Cannot start service (Err=0x00000002).
    -&gt; Error: Cannot open \\.\win32dd.</description>
		<content:encoded><![CDATA[<p>I&#8217;m also seeing crashes on x86 xp sp3:</p>
<p>Error: InstallDriver Cannot start service (Err=0&#215;00000002).<br />
    -&gt; Error: Cannot open \\.\win32dd.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sergey</title>
		<link>http://www.msuiche.net/2009/10/11/windd-1-3-final-x86-and-x64/comment-page-1/#comment-22460</link>
		<dc:creator>Sergey</dc:creator>
		<pubDate>Sun, 13 Dec 2009 15:05:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.msuiche.net/?p=335#comment-22460</guid>
		<description>Win32dd 1.3 Crash on Windows32 SP3!

Error: InstallDriver cannot start service (Err=0x00000002)
Error: Cannot open \\.\win32dd

I tested it with win32dd of USB-Dongle, CD and HDD. Is the same error! 

The System:
Win32 XP Professional SP3 (German)
Athlon AMD64-Dual Core 2100+
4 GB DDR II RAM
No writeblocker</description>
		<content:encoded><![CDATA[<p>Win32dd 1.3 Crash on Windows32 SP3!</p>
<p>Error: InstallDriver cannot start service (Err=0&#215;00000002)<br />
Error: Cannot open \\.\win32dd</p>
<p>I tested it with win32dd of USB-Dongle, CD and HDD. Is the same error! </p>
<p>The System:<br />
Win32 XP Professional SP3 (German)<br />
Athlon AMD64-Dual Core 2100+<br />
4 GB DDR II RAM<br />
No writeblocker</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael</title>
		<link>http://www.msuiche.net/2009/10/11/windd-1-3-final-x86-and-x64/comment-page-1/#comment-21886</link>
		<dc:creator>Michael</dc:creator>
		<pubDate>Tue, 03 Nov 2009 13:39:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.msuiche.net/?p=335#comment-21886</guid>
		<description>Hi Matt,

thanks for the quick reply. Thank you also for updating the help. It looks much more pretty now.
Yes people can use piping, I like it too. But there are many investigators with some kind of fear or phobia of command lines especially of piping. So an option /l, automatically creating a log with the same name as the Dumpfile.log could help a little to get over that fear to force them to use such tools. That&#039;s not vital for me but for some of my class members...
The hash computing on the receiving site (piped into a file ;-)) would document the correct network transmission of the dump in one go. Otherwise I have to use md5sum or something else after the acquisition.
You know criminal procedures are procedures in writing...

CU

Michael</description>
		<content:encoded><![CDATA[<p>Hi Matt,</p>
<p>thanks for the quick reply. Thank you also for updating the help. It looks much more pretty now.<br />
Yes people can use piping, I like it too. But there are many investigators with some kind of fear or phobia of command lines especially of piping. So an option /l, automatically creating a log with the same name as the Dumpfile.log could help a little to get over that fear to force them to use such tools. That&#8217;s not vital for me but for some of my class members&#8230;<br />
The hash computing on the receiving site (piped into a file ;-)) would document the correct network transmission of the dump in one go. Otherwise I have to use md5sum or something else after the acquisition.<br />
You know criminal procedures are procedures in writing&#8230;</p>
<p>CU</p>
<p>Michael</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matt</title>
		<link>http://www.msuiche.net/2009/10/11/windd-1-3-final-x86-and-x64/comment-page-1/#comment-21826</link>
		<dc:creator>Matt</dc:creator>
		<pubDate>Tue, 27 Oct 2009 21:21:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.msuiche.net/?p=335#comment-21826</guid>
		<description>Hi Michael,

Thank you very much for your feedback! 
I was not really sure about report-option-feature but it looks like people really appreciate the detailed output of windd about the memory status. I was like &quot;Oh people can still pipe the output so it doesnt really matter&quot; so I added the &quot;/a&quot; option in case people would use piping.

Why would you see a such feature? What would be the difference with the piped report?

Indeed, for the hash function it is only computed from sender side because this is the most critical part. I assumed the received can still use a third party software like hashdeep from Jesse Kornblum (http://jessekornblum.com/tools/)

I updated the help output for &quot;/c&quot;, &quot;/s&quot; and &quot;/a&quot; options. 

Thanks!</description>
		<content:encoded><![CDATA[<p>Hi Michael,</p>
<p>Thank you very much for your feedback!<br />
I was not really sure about report-option-feature but it looks like people really appreciate the detailed output of windd about the memory status. I was like &#8220;Oh people can still pipe the output so it doesnt really matter&#8221; so I added the &#8220;/a&#8221; option in case people would use piping.</p>
<p>Why would you see a such feature? What would be the difference with the piped report?</p>
<p>Indeed, for the hash function it is only computed from sender side because this is the most critical part. I assumed the received can still use a third party software like hashdeep from Jesse Kornblum (<a href="http://jessekornblum.com/tools/" rel="nofollow">http://jessekornblum.com/tools/</a>)</p>
<p>I updated the help output for &#8220;/c&#8221;, &#8220;/s&#8221; and &#8220;/a&#8221; options. </p>
<p>Thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael</title>
		<link>http://www.msuiche.net/2009/10/11/windd-1-3-final-x86-and-x64/comment-page-1/#comment-21824</link>
		<dc:creator>Michael</dc:creator>
		<pubDate>Tue, 27 Oct 2009 18:03:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.msuiche.net/?p=335#comment-21824</guid>
		<description>Hello again,

I did some testing and really like this new version very much. The inbuilt network capabilities are splendid.

What I miss is an option to write a log. Currently I use a pipe to create one. The hash functionality is vital for forensic purposes. Sadly the option /s is accepted by both the sender and receiver side of the network connection but only the sender computes a hash. Could you add such procedure for the receiving side too to document that the data was transmitted unchanged anyway.

TNX in advance

Michael</description>
		<content:encoded><![CDATA[<p>Hello again,</p>
<p>I did some testing and really like this new version very much. The inbuilt network capabilities are splendid.</p>
<p>What I miss is an option to write a log. Currently I use a pipe to create one. The hash functionality is vital for forensic purposes. Sadly the option /s is accepted by both the sender and receiver side of the network connection but only the sender computes a hash. Could you add such procedure for the receiving side too to document that the data was transmitted unchanged anyway.</p>
<p>TNX in advance</p>
<p>Michael</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael</title>
		<link>http://www.msuiche.net/2009/10/11/windd-1-3-final-x86-and-x64/comment-page-1/#comment-21811</link>
		<dc:creator>Michael</dc:creator>
		<pubDate>Sun, 25 Oct 2009 13:32:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.msuiche.net/?p=335#comment-21811</guid>
		<description>Hey Matt,

great stuff! The only minor thing I&#039;ve found is a truncated description of the /d - option within the help. Seems to work anyway. ;-)

Cu

Michael</description>
		<content:encoded><![CDATA[<p>Hey Matt,</p>
<p>great stuff! The only minor thing I&#8217;ve found is a truncated description of the /d &#8211; option within the help. Seems to work anyway. ;-)</p>
<p>Cu</p>
<p>Michael</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matt</title>
		<link>http://www.msuiche.net/2009/10/11/windd-1-3-final-x86-and-x64/comment-page-1/#comment-21775</link>
		<dc:creator>Matt</dc:creator>
		<pubDate>Tue, 20 Oct 2009 18:09:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.msuiche.net/?p=335#comment-21775</guid>
		<description>First, I have never heard about memdmp. Secondly, dmpchk is an utility from Microsoft. Thirdly, I am not the author of volatility. Forthly, you should read the help information of the utility, the command is:

win32dd.exe /d /f microsoftdump.dmp
for a modern Microsoft dump, to analyze with Windbg.

or 

win32dd.exe /f rawdump.bin
for a raw dump.</description>
		<content:encoded><![CDATA[<p>First, I have never heard about memdmp. Secondly, dmpchk is an utility from Microsoft. Thirdly, I am not the author of volatility. Forthly, you should read the help information of the utility, the command is:</p>
<p>win32dd.exe /d /f microsoftdump.dmp<br />
for a modern Microsoft dump, to analyze with Windbg.</p>
<p>or </p>
<p>win32dd.exe /f rawdump.bin<br />
for a raw dump.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
