30.06.2013 Views

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Log<br />

highlights:<br />

AIR 2.0.0 (Release Date: 17th, Feb 2010)<br />

Start DC3DD (md5 sha512): Tue Jul 27 02:57:07 NZST 2010<br />

Hash will be calculated on /dev/sdc1.<br />

dc3dd 6.12.4 started at 2010-07-27 02:57:07 +1200<br />

command line: dc3dd hash=md5,sha512 hashlog=/tmp/hash.log status=noxfer<br />

if=/dev/sdc1 skip=0 conv=noerror iflag=direct ibs=32768<br />

compiled options: DEFAULT_BLOCKSIZE=32768<br />

sector size: 512 (assumed)<br />

md5 TOTAL: d48a1018a5fbb72b40d36da51e396eb3<br />

sha512 TOTAL:<br />

ff3a752011324ca7b70219c03e230051235aa3cf3a3097698f8a879be9f8e08a64<br />

de7b791e185fa19f58905a2496955302da4a775d31ddaefe26cf31a5e6956f<br />

6297417+0 sectors in<br />

6297417+0 sectors out<br />

Command completed: Tue Jul 27 03:02:10 NZST 2010<br />

Start VERIFY: Tue Jul 27 03:02:10 NZST 2010<br />

Command-line: cat /mnt/new/new/Test002/Test002_AIR_NTFS.* | aircounter<br />

2>> /usr/local/share/air/logs/air.buffer.data | dc3dd hash=md5,sha512<br />

hashlog=/tmp/verify_hash.log status=noxfer <strong>of</strong>=/dev/null<br />

VERIFY SUCCESSFUL: Hashes match<br />

Orig = md5 TOTAL: d48a1018a5fbb72b40d36da51e396eb3<br />

sha512 TOTAL:<br />

ff3a752011324ca7b70219c03e230051235aa3cf3a3097698f8a879be9f8e08a64<br />

de7b791e185fa19f58905a2496955302da4a775d31ddaefe26cf31a5e6956f<br />

Copy = md5 TOTAL: d48a1018a5fbb72b40d36da51e396eb3<br />

sha512 TOTAL:<br />

ff3a752011324ca7b70219c03e230051235aa3cf3a3097698f8a879be9f8e08a64<br />

de7b791e185fa19f58905a2496955302da4a775d31ddaefe26cf31a5e6956f<br />

Command completed: Tue Jul 27 03:07:19 NZST 2010<br />

Results by AFR-01 PASSED AIC-01 PASSED<br />

assertion: AFR-02 PASSED AIC-05 PASSED<br />

AFR-03 PASSED ALOG-01 PASSED<br />

AFR-04 PASSED ALOG-02 PASSED<br />

AFR-05 PASSED ALOG-03 PASSED<br />

AFR-07 PASSED<br />

Analysis: Test achieved the expected Result. Source hashes match verification hashes.<br />

257

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!