Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...
Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...
Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...
Create successful ePaper yourself
Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.
Source<br />
Device:<br />
Drive<br />
Setup:<br />
Partition<br />
Table:<br />
Log<br />
highlights:<br />
FTK Imager 2.9.0.1385 (Release Date: 8 th , Apr 2010)<br />
02 in<strong>for</strong>mation about the acquisition at least including following: device, start<br />
sector, end sector, type and number <strong>of</strong> errors encountered, and start time and<br />
ALOG-<br />
03<br />
end time <strong>of</strong> acquisition.<br />
The tool display correct in<strong>for</strong>mation regarding to the acquisition to the user<br />
and the in<strong>for</strong>mation displayed is consistent with the log file if the log file<br />
function is supported<br />
Drive Model: ST380817AS (80GB)<br />
Serial Number: 5MR18V18<br />
Sector count: 156,301,488<br />
Write blocker: Tableau <strong>Forensic</strong> SATA/IDE Bridge IEEE 1394 SBP2<br />
Device<br />
/dev/sdb: current max LBA: 156,301,488<br />
/dev/sdb: native max LBA: 156,301,488<br />
/dev/sdb: physical max LBA: 156,301,488<br />
/dev/sdb: HPA and DCO are not set<br />
Device Start End #sectors File System<br />
/dev/sdb1 2048 40962047 40960000 NTFS<br />
/dev/sdb2 40962048 83970047 43008000 Ext4<br />
/dev/sdb3 83972096 156350047 72377951 Extended<br />
(Modified)<br />
Created By Access<strong>Data</strong>® FTK® Imager 2.9.0.1385 100406<br />
Case Number: FTK-OutOfBoundaryPartition<br />
Examiner: James Liang<br />
[Drive Geometry]<br />
Cylinders: 9,729<br />
Tracks per Cylinder: 255<br />
Sectors per Track: 63<br />
Bytes per Sector: 512<br />
Sector Count: 156,301,488<br />
[Physical Drive In<strong>for</strong>mation]<br />
Drive Model: Tableau <strong>Forensic</strong> SATA/IDE Bridge IEEE 1394 SBP2 Device<br />
Drive Serial Number: 02cc0e0010903500<br />
Drive Interface Type: 1394<br />
Source data size: 76319 MB<br />
Sector count: 156301488<br />
[Computed Hashes]<br />
MD5 checksum: b42f526d394078656308a9b96aa77188<br />
SHA1 checksum: e2977a0cd2d2608519b1750e980252d01cdb4718<br />
Image In<strong>for</strong>mation:<br />
Acquisition started: Fri Sep 10 02:02:27 2010<br />
Acquisition finished: Fri Sep 10 02:56:06 2010<br />
Segment list:<br />
E:\Image\FTK-OutOfBoundaryPartition.001<br />
E:\Image\FTK-OutOfBoundaryPartition.002<br />
…………………….<br />
E:\Image\FTK-OutOfBoundaryPartition.051<br />
Image Verification Results:<br />
Verification started: Fri Sep 10 02:56:11 2010<br />
Verification finished: Fri Sep 10 03:42:24 2010<br />
MD5 checksum: b42f526d394078656308a9b96aa77188 : verified<br />
SHA1 checksum: e2977a0cd2d2608519b1750e980252d01cdb4718 :<br />
203