4 ms·
Ok. I really only know enough to be dangerous im 17. Looks like I have some changes to make though.
by gregimba 13y ago
Ok. I really only know enough to be dangerous im 17. Looks like I have some changes to make though.
- sneak 13y agoStick with it! I didn't know about shell builtins like 'read' when I was 17 - you're already ahead of millions in the game out there. Read a lot of other people's code to see how stuff is done, it helps a lot.
- bradleyland 13y agoHey, congrats on putting something out there, and for learning something new. Keep it up! At one point in my career, I did electronic discovery and electronic forensics for a bankruptcy trustee as part of their fraud investigation process. One of the central principles is that you want to take every step you can to prevent changes to the examination target. The best way to do this is to mount the volume read-only from a boot CD or separate partition from the examination target. The Digital Ocean documentation says that you can request that your Droplet be switched to a recovery ISO, but you have to make the request through support. I don't know if this is a technical limitation or a policy decision, but it ends up being a good mitigator against a mass examination of data using these techniques. You can see more details about how to request this under the section section "Attempt Recovery with a Recovery ISO": https://www.digitalocean.com/community/articles/how-to-recover-from-file-system-corruption-using-fsck-and-a-recovery-iso https://www.digitalocean.com/community/articles/how-to-recov... You'll want to complete the network setup, but when it comes time to mount your filesystem, use the `-o ro` flag with mount mount /dev/vda /mnt -o ro From there, you can perform a forensic examination of your disk under /mnt, without risk of altering any data.