30.06.2013 Views

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Helix3 Pro R3 (Release Date: 30 th , Dec 2009)<br />

2.15. TC-12 Partially and Completely Hidden by HPA<br />

Test Case TC-12 Partially and Completely Hidden by HPA (Helix3 Pro 2009 R3)<br />

Test &<br />

Case<br />

Summary:<br />

Acquire a partition that is partially or completely hidden by HPA or DCO<br />

Notes: FAT32 partition has been partially hidden by HPA from 150301488 to 156301487.<br />

Assertion: AFR-01 The tool accesses the digital source with a supported access interface<br />

AFR-02 The tool acquires a digital source<br />

AFR-03 The tool operates in an execution environment<br />

AFR-04 The tool creates an image file <strong>of</strong> the digital source<br />

AFR-05 The tool acquires all the visible data sectors from the digital source<br />

AFR-06 The tool acquires all the hidden data sectors from the digital source<br />

AFR-07 All data sectors acquired from the digital source are acquired accurately.<br />

AIC-01 The data represented by an image file is the same as the data acquired by the<br />

tool<br />

AIC-02 The tool creates an image file according to the file <strong>for</strong>mat the user specified.<br />

AIC-05 If multi-file image creation and the image file size is selected, the tool creates<br />

a multi-file image except that one file may be smaller<br />

AIC-06 If the image file integrity check is selected, the tool shall report to the user the<br />

image file has not been changed if the image file has not been changed.<br />

AIC-07 If the image file integrity check is selected, the tool shall report to the user the<br />

image file has been changed if the image file has been changed.<br />

AIC-08 If the image file integrity check is selected, the tool shall report to the user the<br />

image file has been changed and the involved location if the image file has<br />

been changed.<br />

ALOG- If the tool logs any in<strong>for</strong>mation regarding to the acquisition, the in<strong>for</strong>mation is<br />

Source<br />

Device:<br />

Drive<br />

Setup:<br />

Partition<br />

Table:<br />

01<br />

ALOG-<br />

02<br />

ALOG-<br />

03<br />

accurately logged in the log file.<br />

The tool display correct in<strong>for</strong>mation about the acquisition to the user. The<br />

in<strong>for</strong>mation about the acquisition at least including following: device, start<br />

sector, end sector, type and number <strong>of</strong> errors encountered, and start time and<br />

end time <strong>of</strong> acquisition.<br />

The tool display correct in<strong>for</strong>mation regarding to the acquisition to the user<br />

and the in<strong>for</strong>mation displayed is consistent with the log file if the log file<br />

function is supported<br />

AHS-01 The tool reports to the user if any hidden sectors are found<br />

AHS-02 The tool reports to the user that digital source may contain hidden sector but<br />

undetected if the tool is unable to determine whether hidden sectors are<br />

present due to incompatible execution environment<br />

AHS-03 The tool reports to the user that hidden sectors will not be acquired if the tool<br />

is unable to acquire hidden sectors due to incompatible execution<br />

environment<br />

Drive Model: ST380817AS (80GB)<br />

Serial Number: 5MR18V18<br />

Sector count: 156,301,488<br />

Write blocker: N/A<br />

/dev/sdb: current max LBA: 150,301,484<br />

/dev/sdb: native max LBA: 150,301,484<br />

/dev/sdb: physical max LBA: 156,301,488<br />

/dev/sdb: HPA set from sector 150,301,488 to 156,301,487<br />

(Total 736,388 sectors)<br />

Device Start End #sectors File System<br />

/dev/sdb1 63 2104514 2104452 NTFS<br />

/dev/sdb2 2104515 149565149 145460535 Ext3<br />

/dev/sdb3 149565150 156296384 6731234 FAT32 (Partially<br />

HPA)<br />

236

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!