30.06.2013 Views

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Source<br />

Device:<br />

Drive<br />

Setup:<br />

Partition<br />

Table:<br />

Log<br />

highlights:<br />

Results by<br />

assertion:<br />

FTK Imager 2.9.0.1385 (Release Date: 8 th , Apr 2010)<br />

Drive Model: ST380817AS (80GB)<br />

Serial Number: 5MR18V18<br />

Sector count: 156,301,488<br />

Write blocker: Tableau <strong>Forensic</strong> SATA/IDE Bridge IEEE 1394 SBP2<br />

Device<br />

Source hashes<br />

md5: d8235a6c57ddf91c902d42f0e39cb7d5<br />

sha1: b91e9115388276b961e6a94a6322337048734d6c<br />

/dev/sda: current max LBA: 156,301,488<br />

/dev/sda: native max LBA: 156,301,488<br />

/dev/sda: physical max LBA: 156,301,488<br />

/dev/sda: HPA not set<br />

/dev/sda: DCO not set<br />

Device Start End #sectors File System Size<br />

/dev/sdb1 4096 4198399 4194304 HFS 2Gb<br />

/dev/sdb2 4198400 14999551 10801152 HFS+ 5Gb<br />

Unallocated<br />

Created By Access<strong>Data</strong>® FTK® Imager 2.9.0.1385 100406<br />

Starting Sector: 4,096<br />

Sector Count: 4,194,304<br />

Source data size: 2048 MB<br />

Sector count: 4194304<br />

[Computed Hashes]<br />

MD5 checksum: d8235a6c57ddf91c902d42f0e39cb7d5<br />

SHA1 checksum: b91e9115388276b961e6a94a6322337048734d6c<br />

Segment list:<br />

E:\Image\FTK_HFS.001<br />

E:\Image\FTK_HFS.002<br />

Acquisition started: Sun Oct 03 10:18:17 2010<br />

Acquisition finished: Sun Oct 03 10:19:38 2010<br />

Verification started: Sun Oct 03 10:19:38 2010<br />

Verification finished: Sun Oct 03 10:20:07 2010<br />

MD5 checksum: d8235a6c57ddf91c902d42f0e39cb7d5 : verified<br />

SHA1 checksum: b91e9115388276b961e6a94a6322337048734d6c :<br />

verified<br />

AFR-01 PASSED AIC-01 PASSED<br />

AFR-02 PASSED AIC-05 PASSED<br />

AFR-03 PASSED ALOG-01 PASSED<br />

AFR-04 PASSED ALOG-02 PASSED<br />

AFR-05 PASSED ALOG-03 PASSED<br />

AFR-07 PASSED<br />

Analysis: Test achieved the expected Result. Source hashes match verification<br />

hashes.<br />

169

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!