30.06.2013 Views

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Source<br />

Device:<br />

Drive<br />

Setup:<br />

Partition<br />

Table:<br />

Log<br />

highlights:<br />

FTK Imager 2.9.0.1385 (Release Date: 8 th , Apr 2010)<br />

02 in<strong>for</strong>mation about the acquisition at least including following: device, start<br />

sector, end sector, type and number <strong>of</strong> errors encountered, and start time and<br />

ALOG-<br />

03<br />

end time <strong>of</strong> acquisition.<br />

The tool display correct in<strong>for</strong>mation regarding to the acquisition to the user<br />

and the in<strong>for</strong>mation displayed is consistent with the log file if the log file<br />

function is supported<br />

Drive Model: ST380817AS (80GB)<br />

Serial Number: 5MR18V18<br />

Sector count: 156,301,488<br />

Write blocker: Tableau <strong>Forensic</strong> SATA/IDE Bridge IEEE 1394 SBP2<br />

Device<br />

/dev/sdb: current max LBA: 156,301,488<br />

/dev/sdb: native max LBA: 156,301,488<br />

/dev/sdb: physical max LBA: 156,301,488<br />

/dev/sdb: HPA and DCO are not set<br />

Device Start End #sectors File System<br />

/dev/sdb1 2048 40962047 40960000 NTFS<br />

/dev/sdb2 40962048 83970047 43008000 Ext4<br />

/dev/sdb3 83972096 156350047 72377951 Extended<br />

(Modified)<br />

Created By Access<strong>Data</strong>® FTK® Imager 2.9.0.1385 100406<br />

Case Number: FTK-OutOfBoundaryPartition<br />

Examiner: James Liang<br />

[Drive Geometry]<br />

Cylinders: 9,729<br />

Tracks per Cylinder: 255<br />

Sectors per Track: 63<br />

Bytes per Sector: 512<br />

Sector Count: 156,301,488<br />

[Physical Drive In<strong>for</strong>mation]<br />

Drive Model: Tableau <strong>Forensic</strong> SATA/IDE Bridge IEEE 1394 SBP2 Device<br />

Drive Serial Number: 02cc0e0010903500<br />

Drive Interface Type: 1394<br />

Source data size: 76319 MB<br />

Sector count: 156301488<br />

[Computed Hashes]<br />

MD5 checksum: b42f526d394078656308a9b96aa77188<br />

SHA1 checksum: e2977a0cd2d2608519b1750e980252d01cdb4718<br />

Image In<strong>for</strong>mation:<br />

Acquisition started: Fri Sep 10 02:02:27 2010<br />

Acquisition finished: Fri Sep 10 02:56:06 2010<br />

Segment list:<br />

E:\Image\FTK-OutOfBoundaryPartition.001<br />

E:\Image\FTK-OutOfBoundaryPartition.002<br />

…………………….<br />

E:\Image\FTK-OutOfBoundaryPartition.051<br />

Image Verification Results:<br />

Verification started: Fri Sep 10 02:56:11 2010<br />

Verification finished: Fri Sep 10 03:42:24 2010<br />

MD5 checksum: b42f526d394078656308a9b96aa77188 : verified<br />

SHA1 checksum: e2977a0cd2d2608519b1750e980252d01cdb4718 :<br />

203

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!