Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...
Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...
Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...
You also want an ePaper? Increase the reach of your titles
YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.
Source<br />
Device:<br />
Drive<br />
Setup:<br />
Partition<br />
Table:<br />
Log<br />
highlights:<br />
FTK Imager 2.9.0.1385 (Release Date: 8 th , Apr 2010)<br />
sector, end sector, type and number <strong>of</strong> errors encountered, and start time and<br />
end time <strong>of</strong> acquisition.<br />
The tool display correct in<strong>for</strong>mation regarding to the acquisition to the user<br />
ALOGand<br />
the in<strong>for</strong>mation displayed is consistent with the log file if the log file<br />
03<br />
function is supported<br />
AHS-01 The tool reports to the user if any hidden sectors are found<br />
The tool reports to the user that digital source may contain hidden sector but<br />
AHS-02 undetected if the tool is unable to determine whether hidden sectors are<br />
present due to incompatible execution environment<br />
The tool reports to the user that hidden sectors will not be acquired if the tool<br />
AHS-03 is unable to acquire hidden sectors due to incompatible execution<br />
environment<br />
Drive Model: ST380817AS (80GB)<br />
Serial Number: 5MR18V18<br />
Sector count: 156,301,488<br />
Write blocker: N/A<br />
Source hashes<br />
MD5 checksum: 554357b44e0334f254e80ab537a299c7<br />
SHA1 checksum: aa314705b7addb0bf230974b30967fa74082f490<br />
/dev/sdb: current max LBA: 150,301,484<br />
/dev/sdb: native max LBA: 150,301,484<br />
/dev/sdb: physical max LBA: 156,301,488<br />
/dev/sdb: HPA set from sector 150,301,488 to 156,301,487 (Total<br />
5,999,999 sectors)<br />
Device Start End #sectors File System<br />
/dev/sdb1 63 2104514 2104452 NTFS<br />
/dev/sdb2 2104515 149565149 145460535 Ext3<br />
/dev/sdb3 149565150 156296384 6731235 FAT32 (Partially<br />
HPA)<br />
NOTICE: Imaging failed with the following error:<br />
block index out <strong>of</strong> bounds<br />
This image is incomplete!<br />
Created By Access<strong>Data</strong>® FTK® Imager 2.9.0.1385 100406<br />
Case In<strong>for</strong>mation:<br />
Case Number: FAT32 Partition partically hidden<br />
Evidence Number:<br />
Unique Description:<br />
Examiner: James Liang<br />
Notes:<br />
--------------------------------------------------------------<br />
In<strong>for</strong>mation <strong>for</strong> E:\Image\FAT32_Part_Hidden:<br />
Physical Evidentiary Item (Source) In<strong>for</strong>mation:<br />
[Partition In<strong>for</strong>mation]<br />
Starting Sector: 149,565,150<br />
Sector Count: 6,731,235<br />
Source data size: 3286 MB<br />
Sector count: 6731235<br />
[Computed Hashes]<br />
MD5 checksum: 397a300fac799fd8c78bd5951c1a626e<br />
SHA1 checksum: 3c91b102f596f0e29bf63ccb007996c80d484a7c<br />
Image In<strong>for</strong>mation:<br />
198