30.06.2013 Views

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Source<br />

Device:<br />

Drive<br />

Setup:<br />

Partition<br />

Table:<br />

Log<br />

highlights:<br />

ALOG-<br />

03<br />

Helix3 Pro R3 (Release Date: 30 th , Dec 2009)<br />

The tool display correct in<strong>for</strong>mation regarding to the acquisition to the user<br />

and the in<strong>for</strong>mation displayed is consistent with the log file if the log file<br />

function is supported<br />

Drive Model: ST380817AS (80GB)<br />

Serial Number: 5MR18V18<br />

Sector count: 156,301,488<br />

Write blocker: Tableau <strong>Forensic</strong> SATA/IDE Bridge IEEE 1394 SBP2<br />

Device<br />

/dev/sdb: current max LBA: 156,301,488<br />

/dev/sdb: native max LBA: 156,301,488<br />

/dev/sdb: physical max LBA: 156,301,488<br />

/dev/sdb: HPA and DCO are not set<br />

Device Start End #sectors File System<br />

/dev/sdb1 2048 40962047 40960000 NTFS<br />

/dev/sdb2 40962048 83970047 43008000 Ext4<br />

/dev/sdb3 83972096 156301311 72329125 Extended<br />

Created By Helix3 Pro 2009R3<br />

SYSTEM INFORMATION<br />

OS Name Windows XP<br />

OS Mode Workstation<br />

OS Patch Service Pack 3<br />

OS Build 5.1.2600<br />

Computer Name JAMES-212DFE2EF<br />

User Name Administrator<br />

Administrator True<br />

NIC 1 - IP 192.168.182.134<br />

NIC 1 - MAC 00:0C:29:E1:F8:FA<br />

NIC 1 - Subnet 255.255.255.0<br />

DISK INFORMATION<br />

physical True<br />

size 80023749120<br />

name PhysicalDrive2<br />

mount PhysicalDrive2<br />

serialnumber 3.42<br />

system AS<br />

firmware ST380817<br />

type Fixed hard disk<br />

Whole<strong>Disk</strong> True<br />

ACQUISITION INFORMATION<br />

Acquire Format: RAW<br />

Acquisition Start: 2010-09-12 23:58:54<br />

Acquisition Stop 2010-09-13 04:17:59<br />

Output File(s):<br />

G:\Image\Helix-UnReadableMBR.001<br />

G:\Image\Helix-UnReadableMBR.002<br />

……………………………..<br />

G:\Image\Helix-UnReadableMBR.038<br />

Verification: Passed<br />

Hash(es):<br />

MD5: 2ab63e47f402406afed31dad063df7f8<br />

SHA1: d337f09ba2b9069668c70a14a2fc87a3b21a5887<br />

243

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!