30.06.2013 Views

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Source<br />

Device:<br />

Drive<br />

Setup:<br />

Partition<br />

Table:<br />

Log<br />

highlights:<br />

Results by<br />

assertion:<br />

Helix3 Pro R3 (Release Date: 30 th , Dec 2009)<br />

consistent with the log file if the log file function is supported<br />

Drive Model: ST380811 AS (80GB)<br />

Serial Number: 6PS2CA4Z<br />

Sector count: 156,296,385<br />

Write blocker: N/A<br />

Source hashes<br />

MD5: d8235a6c57ddf91c902d42f0e39cb7d5<br />

SHA1: b91e9115388276b961e6a94a6322337048734d6c<br />

/dev/sdb: current max LBA: 156,296,385<br />

/dev/sdb: native max LBA: 156,296,385<br />

/dev/sdb: physical max LBA: 156,296,385<br />

/dev/sdb: HPA not set<br />

/dev/sdb: DCO not set<br />

Device Start End #sectors File System Size<br />

/dev/sdb1 4096 4198399 4194304 HFS 2Gb<br />

/dev/sdb2 4198400 14999551 10801152 HFS+ 5Gb<br />

Unallocated<br />

AFR-01 PASSED AIC-01 N/A<br />

AFR-02 FAILED AIC-05 N/A<br />

AFR-03 PASSED ALOG-01 N/A<br />

AFR-04 FAILED ALOG-02 N/A<br />

AFR-05 N/A ALOG-03 N/A<br />

AFR-07 N/A<br />

Analysis: Test FAILED to achieve the expected Result. Helix 3 Pro cannot identify<br />

the HFS or HFS+ partitions<br />

2.10. TC-03-HPA<br />

Test Case TC-03-HPA (Helix3 Pro 2009 R3)<br />

Test &<br />

Case<br />

Summary:<br />

TC-03 Acquire a hard drive with hidden sectors to an image file<br />

Notes: HPA actived<br />

Assertion: AFR-01 The tool accesses the digital source with a supported access interface<br />

AFR-02 The tool acquires a digital source<br />

AFR-03 The tool operates in an execution environment<br />

AFR-04 The tool creates an image file <strong>of</strong> the digital source<br />

AFR-05 The tool acquires all the visible data sectors from the digital source<br />

AFR-06 The tool acquires all the hidden data sectors from the digital source<br />

225

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!