Last week my friend brought me an evidence file duplicated from a Linux server, which distribution is CentOS 5.0 and the I 18n is ZH-TW. She wanna know whether there is any malware on this Linux server or not. Ok. Let's get to work. I Add this evidence and do evidence Process. Guess what??? EnCase could not recognize Chinese character folder Names/filenames, and those folder Names/filenames become Hier Oglyphics. I am very disappointed and don ' t know to say to my friend ... I guess I had to explain why EnCase could need night vision goggles when examining Linux platform evidence files. It ' s too ridiculous!
Needless to say, my friend also could not believe the #1 forensic tool-encase should has problems like that. Fortunately I still have the another options like FTK or x-ways forensics to take over the this case. You guys could take a look at screenshot below. I mount These evidence files by using FTK Imager Lite. You could see the Chinese character folder Names/filenames now. I ' d like to remind Ftk Imager Lite are a free tool ...
EnCase V7 could not recognize Chinese character folder Names/file names on Linux Platform