30.06.2013 Views

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Source<br />

Device:<br />

Drive<br />

Setup:<br />

Log<br />

highlights:<br />

Results by<br />

assertion:<br />

AIR 2.0.0 (Release Date: 17th, Feb 2010)<br />

the tool creates a multi-file image except that one file may be<br />

smaller<br />

ALOG-01 If the tool logs any in<strong>for</strong>mation regarding to the acquisition,<br />

the in<strong>for</strong>mation is accurately logged in the log file.<br />

ALOG-02 The tool display correct in<strong>for</strong>mation about the acquisition to<br />

the user.<br />

ALOG-03 The tool display correct in<strong>for</strong>mation regarding to the<br />

acquisition to the user and the in<strong>for</strong>mation displayed is<br />

consistent with the log file if the log file function is supported<br />

Drive Model: Kingston DT 101 II (16 GB)<br />

Serial Number: 5MR18V18<br />

Sector count: 31,272,544<br />

Write blocker: Tableau T8 <strong>Forensic</strong> USB Bridge<br />

Source hashes<br />

MD5: 7ca6d932d51138e1a8e4cfbb9540483c<br />

SHA1: fc4d8c39e052331e15a0b7bdd5ae08804bbab2a6<br />

/dev/sda: current max LBA: 31,272,544<br />

/dev/sda: native max LBA: 31,272,544<br />

/dev/sda: physical max LBA: 31,272,544<br />

/dev/sda: HPA not set<br />

/dev/sda: DCO not set<br />

Start DC3DD (md5 sha1): Thu Jul 1 10:59:00 NZST 2010<br />

command line: dc3dd hash=md5,sha1 hashlog=/tmp/hash.log<br />

status=noxfer if=/dev/sdc skip=0 conv=noerror,sync iflag=direct<br />

ibs=32768<br />

compiled options: DEFAULT_BLOCKSIZE=32768<br />

sector size: 512 (assumed)<br />

md5 TOTAL: 7ca6d932d51138e1a8e4cfbb9540483c<br />

sha1 TOTAL: fc4d8c39e052331e15a0b7bdd5ae08804bbab2a6<br />

31272544+0 sectors in<br />

31272544+0 sectors out<br />

Command completed: Thu Jul 1 11:14:44 NZST 2010<br />

Start VERIFY: Thu Jul 1 11:14:44 NZST 2010<br />

dc3dd if=/mnt/Images/Caine/caine.dd hash=md5,sha1 conv=noerror,sync<br />

hashlog=/tmp/verify_hash.log status=noxfer | air-counter 2>><br />

/usr/local/share/air/logs/air.buffer.data > /dev/null<br />

VERIFY SUCCESSFUL: Hashes match<br />

Orig = md5 TOTAL: 7ca6d932d51138e1a8e4cfbb9540483c<br />

sha1 TOTAL: fc4d8c39e052331e15a0b7bdd5ae08804bbab2a6<br />

Copy = md5 TOTAL: 7ca6d932d51138e1a8e4cfbb9540483c<br />

sha1 TOTAL: fc4d8c39e052331e15a0b7bdd5ae08804bbab2a6<br />

Command completed: Thu Jul 1 11:18:48 NZST 2010<br />

AFR-01 PASSED AIC-01 PASSED<br />

AFR-02 PASSED AIC-05 PASSED<br />

AFR-03 PASSED ALOG-01 PASSED<br />

AFR-04 PASSED ALOG-02 PASSED<br />

AFR-05 PASSED ALOG-03 PASSED<br />

AFR-07 PASSED<br />

Analysis: Test achieved the expected Result. Source hashes match verification<br />

hashes.<br />

255

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!