30.06.2013 Views

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

2. Linux distributions Ubuntu and Gentoo are required <strong>for</strong> better stability. (the<br />

project used Ubuntu based Linux Distribution)<br />

3. Perl/Tk must be installed. If Perl/Tk is not installed on your system, install-air<br />

will attempt to download it itself.<br />

4. Install program autoconf-1.10.1 and gperf<br />

5. Install dc3dd (x.xx.x indicates the version <strong>of</strong> dc3dd. Our project used version<br />

6.12.4)<br />

a) Unpack the installation file:<br />

$ tar zxvf dc3dd.x.xx.x.tar.gz<br />

b) Navigate to the unpacked file directory and install:<br />

$ ./configure<br />

$ make<br />

$ sudo make install<br />

6. Installation <strong>of</strong> AIR (x.x.x indicates the version <strong>of</strong> AIR. Our project used<br />

version 2.0.0)<br />

a) Unzip the installation file:<br />

$ sudo gunzip install-air-x.x.x.gz<br />

b) Change the ownership <strong>of</strong> the installation file<br />

$ chmod +x install-air-x.x.x<br />

$ sudo ./install-air-x.x.x<br />

4.6.2 Acquisition – AIR (Common in most Test Scenarios)<br />

1. Connect the test hard drive to the Windows machine using the specified<br />

physical interface. Connect to the hardware writeblocker if the test case is<br />

required.<br />

2. Open the Terminal and type in the command “sudo air” to run AIR.<br />

3. In the field source device type in source drive (Use command “fdisk -l” to<br />

verify). Partition can also be specified in here.<br />

4. In the field destination device type in destination drive (Mount the destination<br />

drive in the system)<br />

5. Choose md5 as Hash 1 and sha1 as Hash 2. Choose Verify as Yes.<br />

6. Select Use DC3DD and Split Image to 2047 Mbytes<br />

147

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!