Pidgin, formerly known as Gaim, is a multi-protocol instant messaging (IM) client that supports communication on most of the popular IM networks. Pidgin is chiefly popular under Linux, and is available for Windows, BSD and other UNIX versions. This article presents a number of traces that are left behind after the use of Pidgin on Linux, enabling digital investigators to search for and interpret instant messaging activities, including online conversations and file transfers. Specifically, the contents and structures of user settings, log files, contact files and the swap partition are discussed. In addition looking for such information in active files on a computer, forensic examiners can recover deleted items by searching a hard drive for file signatures and known file structures detailed in this article.
[1]
Wouter S. van Dongen.
Forensic artefacts left by Windows Live Messenger 8.0
,
2007,
Digit. Investig..
[2]
Mike Dickson.
An examination into MSN Messenger 7.5 contact identification
,
2006,
Digit. Investig..
[3]
Mike Dickson.
An examination into Yahoo Messenger 7.0 contact identification
,
2006,
Digit. Investig..
[4]
Mike Dickson.
An examination into AOL Instant Messenger 5.5 contact identification
,
2006,
Digit. Investig..
[5]
Mike Dickson.
An examination into Trillian basic 3.x contact identification
,
2007,
Digit. Investig..