30.06.2013 Views

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Source<br />

Device:<br />

Drive<br />

Setup:<br />

Partition<br />

Table:<br />

Log<br />

highlights:<br />

AHS-03<br />

FTK Imager 2.9.0.1385 (Release Date: 8 th , Apr 2010)<br />

The tool reports to the user that hidden sectors will not be acquired if the tool<br />

is unable to acquire hidden sectors due to incompatible execution<br />

environment<br />

Drive Model: ST380817AS (80GB)<br />

Serial Number: 5MR18V18<br />

Sector count: 156,301,488<br />

Write blocker: N/A<br />

/dev/sdb: current max LBA: 149,565,150<br />

/dev/sdb: native max LBA: 149,565,150<br />

/dev/sdb: physical max LBA: 156,301,488<br />

/dev/sdb: HPA set from sector 149,565,150 to 156,301,487 (Total<br />

6,736,337 sectors)<br />

Device Start End #sectors File System<br />

/dev/sdb1 63 2104514 2104452 NTFS<br />

/dev/sdb2 2104515 149565149 145460535 Ext3<br />

/dev/sdb3 149565150 156296384 6731234 FAT32 (Entire<br />

HPA)<br />

Results by<br />

assertion: AFR-01 PASSED AIC-01 FAILED AHS-02 FAILED<br />

AFR-02 PASSED AIC-02 FAILED AHS-03 FAILED<br />

AFR-03 PASSED AIC-05 FAILED ALOG-01 FAILED<br />

AFR-04 FAILED AIC-06 FAILED ALOG-02 FAILED<br />

AFR-05 FAILED AIC-07 FAILED ALOG-03 FAILED<br />

AFR-06 FAILED AIC-08 FAILED<br />

AFR-07 FAILED AHS-01 FAILED<br />

Analysis: Test FAILED to achieve the expected Result. FTK Imager is able to detect<br />

the partition in<strong>for</strong>mation correctly. However, FTK Imager freezes at the<br />

preparing to create image.<br />

200

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!