30.06.2013 Views

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Source<br />

Device:<br />

Drive<br />

Setup:<br />

Partition<br />

Table:<br />

Log<br />

highlights:<br />

FTK Imager 2.9.0.1385 (Release Date: 8 th , Apr 2010)<br />

sector, end sector, type and number <strong>of</strong> errors encountered, and start time and<br />

end time <strong>of</strong> acquisition.<br />

The tool display correct in<strong>for</strong>mation regarding to the acquisition to the user<br />

ALOGand<br />

the in<strong>for</strong>mation displayed is consistent with the log file if the log file<br />

03<br />

function is supported<br />

AHS-01 The tool reports to the user if any hidden sectors are found<br />

The tool reports to the user that digital source may contain hidden sector but<br />

AHS-02 undetected if the tool is unable to determine whether hidden sectors are<br />

present due to incompatible execution environment<br />

The tool reports to the user that hidden sectors will not be acquired if the tool<br />

AHS-03 is unable to acquire hidden sectors due to incompatible execution<br />

environment<br />

Drive Model: ST380817AS (80GB)<br />

Serial Number: 5MR18V18<br />

Sector count: 156,301,488<br />

Write blocker: N/A<br />

Source hashes<br />

MD5 checksum: 554357b44e0334f254e80ab537a299c7<br />

SHA1 checksum: aa314705b7addb0bf230974b30967fa74082f490<br />

/dev/sdb: current max LBA: 150,301,484<br />

/dev/sdb: native max LBA: 150,301,484<br />

/dev/sdb: physical max LBA: 156,301,488<br />

/dev/sdb: HPA set from sector 150,301,488 to 156,301,487 (Total<br />

5,999,999 sectors)<br />

Device Start End #sectors File System<br />

/dev/sdb1 63 2104514 2104452 NTFS<br />

/dev/sdb2 2104515 149565149 145460535 Ext3<br />

/dev/sdb3 149565150 156296384 6731235 FAT32 (Partially<br />

HPA)<br />

NOTICE: Imaging failed with the following error:<br />

block index out <strong>of</strong> bounds<br />

This image is incomplete!<br />

Created By Access<strong>Data</strong>® FTK® Imager 2.9.0.1385 100406<br />

Case In<strong>for</strong>mation:<br />

Case Number: FAT32 Partition partically hidden<br />

Evidence Number:<br />

Unique Description:<br />

Examiner: James Liang<br />

Notes:<br />

--------------------------------------------------------------<br />

In<strong>for</strong>mation <strong>for</strong> E:\Image\FAT32_Part_Hidden:<br />

Physical Evidentiary Item (Source) In<strong>for</strong>mation:<br />

[Partition In<strong>for</strong>mation]<br />

Starting Sector: 149,565,150<br />

Sector Count: 6,731,235<br />

Source data size: 3286 MB<br />

Sector count: 6731235<br />

[Computed Hashes]<br />

MD5 checksum: 397a300fac799fd8c78bd5951c1a626e<br />

SHA1 checksum: 3c91b102f596f0e29bf63ccb007996c80d484a7c<br />

Image In<strong>for</strong>mation:<br />

198

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!