30.06.2013 Views

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Source<br />

Device:<br />

Drive<br />

Setup:<br />

Partition<br />

Table:<br />

Log<br />

highlights:<br />

Results by<br />

assertion:<br />

FTK Imager 2.9.0.1385 (Release Date: 8 th , Apr 2010)<br />

ALOG-03 The tool display correct in<strong>for</strong>mation regarding to the<br />

acquisition to the user and the in<strong>for</strong>mation displayed is<br />

consistent with the log file if the log file function is supported<br />

Drive Model: ST380811 AS (80GB)<br />

Serial Number: 6PS2CA4Z<br />

Sector count: 156,296,385<br />

Write blocker: Tableau <strong>Forensic</strong> SATA/IDE Bridge IEEE 1394 SBP2<br />

Device<br />

Source hashes<br />

MD5 checksum: 2c22fded78dc8ccc2c935944883a2e1b<br />

SHA1 checksum: 10eaa99a609cd8d215c9dc5a68f46e2e0d5c68c5<br />

/dev/sdb: current max LBA: 156,296,385<br />

/dev/sdb: native max LBA: 156,296,385<br />

/dev/sdb: physical max LBA: 156,296,385<br />

/dev/sdb: HPA not set<br />

/dev/sdb: DCO not set<br />

Device Start End #Sectors File System<br />

/dev/sdb1 63 4192964 4192902 NTFS<br />

/dev/sdb2 4193028 6297479 2104452 FAT32<br />

/dev/sdb3 6297543 10490444 4192902 FAT16<br />

/dev/sdb4 10490508 12594959 2104452 Ext2<br />

/dev/sdb5 12595023 14699474 2104452 Ext3<br />

/deb/sdb6 18892503 19149479 256977 Swap<br />

Created By Access<strong>Data</strong>® FTK® Imager 2.9.0.1385 100406<br />

Starting Sector: 4,193,028<br />

Sector Count: 2,104,452<br />

Source data size: 1027 MB<br />

MD5 checksum: 2c22fded78dc8ccc2c935944883a2e1b<br />

SHA1 checksum: 10eaa99a609cd8d215c9dc5a68f46e2e0d5c68c5<br />

Acquisition started: Tue Jul 27 07:07:32 2010<br />

Acquisition finished: Tue Jul 27 07:08:15 2010<br />

Verification started: Tue Jul 27 07:08:15 2010<br />

Verification finished: Tue Jul 27 07:08:20 2010<br />

MD5 checksum: 2c22fded78dc8ccc2c935944883a2e1b : verified<br />

SHA1 checksum: 10eaa99a609cd8d215c9dc5a68f46e2e0d5c68c5 :<br />

verified<br />

AFR-01 PASSED AIC-01 PASSED<br />

AFR-02 PASSED AIC-05 PASSED<br />

AFR-03 PASSED ALOG-01 PASSED<br />

AFR-04 PASSED ALOG-02 PASSED<br />

AFR-05 PASSED ALOG-03 PASSED<br />

AFR-07 PASSED<br />

Analysis: Test achieved the expected Result. Source hashes match verification<br />

hashes.<br />

166

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!