banner
Caine is a simple Ubuntu 12.04 customized for the computer forensics, all you need to read is here (this is a collection of infos for the old caine releases) and the rest is: http://linuxleo.com/Docs/linuxintro-LEFE-3.78.pdf and all the single manuals of the tools (e.g. the Sleuthkit, Autopsy, Foremost,etc. etc.)

Booting Caine via PXE by Hans Peter Merkel

1. Mounting policy of CAINE
The mounting policy for any internal or external devices adopted by CAINE: never mount automatically any device and when the user clicks on the device icon the system will mount it in read only mode on loop device.
- A user cannot mount a device through the
Disk Mounter applet, but only by Terminal Window or by Mounter (GUI) Mounter and the system will always mounted with the following options: ro,noatime,noexec,nosuid,nodev,noload.
For UMOUNTING a device you can use Caja by root (eg. gksudo Caja) or by terminal window (xterm or sudo umount) or Mounter GUI
General Information:

A green disk icon means the system is SAFE and will mount devices READ-ONLY.
A red disk icon means WARNING, mounted devices will be WRITEABLE.

Instructions:

Left-click the disk icon to mount a device.
Right-click the disk icon to change the system mount policy.
Middle-click will close the mounter application. Relaunch from the menu.

The mounted devices will not be affected by mount policy changes. Only subsequent mounting operations will be affected.

- If the user decides to mount a device via terminal, he can use the “mount” command but all the mount options must be specified.
- If the user wants to mount and write on an NTFS media should instead use the "ntfs-3g" command (e.g., $ sudo ntfs-3g -o rw /dev/sda1 /media/sda1).

  • sudo ntfs-3g -o rw /device-path /your-mount-point


You can redirect the output on an RW mounted device in these ways:
  • Terminal window --> sudo su --> (eg. fdisk -lu > /media/sdb1/fdisk.txt)
  • Terminal window --> output redirect in, for example: /home/caine, then sudo cp fdisk.txt /media/sdb1
  • sudo bash -c "fdisk -lu > /media/sdb1/fdisk.txt"


The ext3 driver will be ignored when ext2 and ext3 partitions are mounted in the future and the ext2 driver used instead. This protects any ext3 partitions from a forensic point-of-view. Ext2 does not use journaling, so when an ext3 partition is mounted, there is no danger of modifying the meta-data when increasing the count inside said journal.
Applying a special patch (Maxim Suhanov's patch) we fixed the bug, that changed the journal of the ext3/ext4 file system, when the computer was switch off not using the shutdown procedure. Fixed in the fstab: forbidding the auto-mounting of the MMCs and put a control for the "esotic names" like /dev/sdad1

Bash Scripts Tools directory:
the tools MUST be launched by sudo sh script_name.sh

2. LiveUSB issue
Cannot create LiveUSB Caine from this distro, you have to DOWNLOAD NBCaine from Caine's website to get it! (for Caine 3.0 previous releases) OR if you need CAINE on pendrive (USB), you can sobstitute the file /usr/share/initramfs-tools/scripts/casper with THIS and use your preferred tool for making it.

3. Installed version
After installing Caine on your HD, you have to edit the /usr/sbin/rbfstab, changing swapoff -a in swapon -a and the row swap) OPTIONS=ro,noauto ;; with #swap) OPTIONS=ro,noauto ;;. Or simply write sudo rbfstab -r
If you need CAINE on pendrive (USB), you can sobstitute the file /usr/share/initramfs-tools/scripts/casper with THIS and use your preferred tool for making it.
After the installation, CHANGE your /etc/sudoers with THIS, for avoiding the password asking after the login.

4. Language Support
The CAINE report supports the following languages:
English, Italian, French, German and Portuguese. The translations of report template in French and German were kindly made by Guy Vucken, developer of Guymager, who previously cooperate with the team to integrate his forensic software inside CAINE. The Portuguese translation has been gently provided by Tony Rodrigues a portuguese Digital and Computer Forensics expert.Turkish thanks to Burkay Sucu.

We hope to increase the number of translations in the future. If you wish to participate by providing the translation of the report in your language or if you report a translation mistake, please contact the CAINE team.

CAINE Live CD uses the USA keyboard layout. We suggest to change the layout using the program “Keyboard Preferences” in System -> Preferences, in the GNOME menu or using the command “
sudo setxkbmap -layout xy” (xy = “it”, “gb”, “de”...) in the command line. BTW there is a launcher on the desktop.
In the CAINE TEXT MODE only, change the keyboard layout by "sudo loadkeys xy" (xy = “it”, “gb”, “de”...)



4. CAINE building
CAINE Distro has been realized from Ubuntu Linux 12.04 using also Remastersys developed by Tony Brijeski and released with GNU GPL license.