30.06.2013 Views

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Drive<br />

Setup:<br />

Partition<br />

Setup:<br />

Log<br />

highlights:<br />

Results by<br />

assertion:<br />

FTK Imager 2.9.0.1385 (Release Date: 8 th , Apr 2010)<br />

Source Smart image hashes<br />

MD5 checksum: f7c2c38630b0c995732a87cce003dcca<br />

SHA1 checksum: 2043d334ef1ee9c1749427b249b3c983d4fcc8ed<br />

Total sectors: 2104452 (1024MB)<br />

/dev/sda: current max LBA: 156,296,385<br />

/dev/sda: native max LBA: 156,296,385<br />

/dev/sda: physical max LBA: 156,296,385<br />

/dev/sda: HPA not set<br />

/dev/sda: DCO not set<br />

Device Start End #Sectors File System<br />

/dev/sda1 63 41945714 41945652 HPFS/NTFS<br />

/dev/sda2 4192965 156296384 152103420 Extended<br />

/dev/sda5 4193028 6297479 2104452 FAT32<br />

/dev/sda6 6297543 10490444 4192902 FAT16<br />

/dev/sda7 10490508 12594959 1052226 Ext2<br />

/dev/sda8 12595023 14699474 2104452 Ext3<br />

/dev/sda9 14699538 18892439 4192902 HPFS/NTFS<br />

/dev/sda10 18892503 19149479 256977 Swap<br />

unallocated 19149480 156296384 137146905 Empty<br />

Created By Access<strong>Data</strong>® FTK® Imager 2.9.0.1385 100406<br />

MD5 verification hash: f7c2c38630b0c995732a87cce003dcca<br />

SHA1 verification hash: 2043d334ef1ee9c1749427b249b3c983d4fcc8ed<br />

Bytes per Sector: 512<br />

Sector Count: 2,104,452<br />

Image Type: SMART ew-compressed<br />

Acquired on OS: Windows 200x<br />

Acquired using: ADI2.9.0.13<br />

Acquire date: 8/10/2010 3:37:58 PM<br />

System date: 8/10/2010 3:37:58 PM<br />

Source data size: 1027 MB<br />

Sector count: 2104452<br />

MD5 checksum: f7c2c38630b0c995732a87cce003dcca<br />

SHA1 checksum: 2043d334ef1ee9c1749427b249b3c983d4fcc8ed<br />

Acquisition started: Wed Aug 11 03:50:31 2010<br />

Acquisition finished: Wed Aug 11 03:50:58 2010<br />

Segment list:<br />

G:\new\Test005-AltFor-FTK\Test005-FTK-SmartToDD.001<br />

Verification started: Wed Aug 11 03:50:58 2010<br />

Verification finished: Wed Aug 11 03:51:04 2010<br />

MD5 checksum: f7c2c38630b0c995732a87cce003dcca : verified<br />

SHA1 checksum: 2043d334ef1ee9c1749427b249b3c983d4fcc8ed :<br />

verified<br />

AFR-03 PASSED ALOG-01 PASSED<br />

AFR-09 PASSED ALOG-02 PASSED<br />

ALOG-03 PASSED<br />

Analysis: Test achieved the expected Result. Source hashes match verification<br />

hashes and the hash <strong>of</strong> the original Smart image.<br />

195

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!