30.06.2013 Views

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

3.5. TC-02-Ext3<br />

AIR 2.0.0 (Release Date: 17th, Feb 2010)<br />

Test Case TC-02-Ext3 (AIR 2.0.0)<br />

Test &<br />

Case<br />

Acquire a digital source that supported by the tools to an image file<br />

Summary: Notes: Acquire Ext3 partition only<br />

Assertion: AFR-01 The tool accesses the digital source with a supported access<br />

interface<br />

AFR-02 The tool acquires a digital source<br />

AFR-03 The tool operates in an execution environment<br />

AFR-04 The tool creates an image file <strong>of</strong> the digital source<br />

AFR-05 The tool acquires all the visible data sectors from the digital<br />

source<br />

AFR-07 All data sectors acquired from the digital source are acquired<br />

accurately.<br />

AIC-01 The data represented by an image file is the same as the data<br />

acquired by the tool<br />

AIC-05 If multi-file image creation and the image file size is selected,<br />

the tool creates a multi-file image except that one file may be<br />

smaller<br />

Source<br />

ALOG-01 If the tool logs any in<strong>for</strong>mation regarding to the acquisition,<br />

the in<strong>for</strong>mation is accurately logged in the log file.<br />

ALOG-02 The tool display correct in<strong>for</strong>mation about the acquisition to<br />

the user.<br />

ALOG-03 The tool display correct in<strong>for</strong>mation regarding to the<br />

acquisition to the user and the in<strong>for</strong>mation displayed is<br />

consistent with the log file if the log file function is supported<br />

Drive Model: ST380817AS (80GB)<br />

Device: Serial Number: 5MR18V18<br />

Sector count: 156,301,488<br />

Write blocker: Tableau <strong>Forensic</strong> SATA/IDE Bridge IEEE 1394 SBP2<br />

Device<br />

Drive Source hashes<br />

Setup: md5: dd010be4950db17ebe05b213cd57f6c4<br />

sha512:<br />

5eb120505c2daf982a42633d5ba1cc0ae45626adab95c9454a3d609be7557a<br />

01f0ad248d28f42f2b2ad8c6e2814473d027cdb495448491f157c37581ea5a<br />

456f<br />

/dev/sda: current max LBA: 156,301,488<br />

/dev/sda: native max LBA: 156,301,488<br />

/dev/sda: physical max LBA: 156,301,488<br />

/dev/sda: HPA not set<br />

/dev/sda: DCO not set<br />

Partition<br />

Table:<br />

Device<br />

/dev/sdb1<br />

/dev/sdb2<br />

Start<br />

63<br />

6297543<br />

End<br />

6297479<br />

10490444<br />

#sectors<br />

6297417<br />

4192902<br />

File System<br />

NTFS<br />

Ext2<br />

Size<br />

3Gb<br />

2Gb<br />

/dev/sdb3 10490508 14683409 4192902 Ext3 2Gb<br />

/dev/sdb4 14683473 16787924 2104452 FAT16 1Gb<br />

/deb/sdb6 18892503 20996954 2104452 Swap 1Gb<br />

Log Start DC3DD (md5 sha512): Tue Jul 27 03:18:10 NZST 2010<br />

highlights: dc3dd hash=md5,sha512 hashlog=/tmp/hash.log status=noxfer<br />

260

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!