30.06.2013 Views

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

3.9. TC-02-HFS+<br />

Test Case TC-02-HFS+ (AIR 2.0.0)<br />

Test &<br />

Case<br />

Summary:<br />

AIR 2.0.0 (Release Date: 17th, Feb 2010)<br />

Acquire a digital source that supported by the tools to an image file<br />

Notes: Acquire Mac partition type HFS+ partition only<br />

Assertion: AFR-01 The tool accesses the digital source with a supported access<br />

interface<br />

AFR-02 The tool acquires a digital source<br />

AFR-03 The tool operates in an execution environment<br />

AFR-04 The tool creates an image file <strong>of</strong> the digital source<br />

AFR-05 The tool acquires all the visible data sectors from the digital<br />

source<br />

AFR-07 All data sectors acquired from the digital source are acquired<br />

accurately.<br />

AIC-01 The data represented by an image file is the same as the data<br />

acquired by the tool<br />

AIC-05 If multi-file image creation and the image file size is selected,<br />

the tool creates a multi-file image except that one file may be<br />

smaller<br />

ALOG-01 If the tool logs any in<strong>for</strong>mation regarding to the acquisition,<br />

the in<strong>for</strong>mation is accurately logged in the log file.<br />

ALOG-02 The tool display correct in<strong>for</strong>mation about the acquisition to<br />

the user.<br />

ALOG-03 The tool display correct in<strong>for</strong>mation regarding to the<br />

acquisition to the user and the in<strong>for</strong>mation displayed is<br />

Source<br />

Device:<br />

Drive<br />

Setup:<br />

Partition<br />

Table:<br />

Log<br />

highlights:<br />

consistent with the log file if the log file function is supported<br />

Drive Model: ST380817AS (80GB)<br />

Serial Number: 5MR18V18<br />

Sector count: 156,301,488<br />

Write blocker: Tableau <strong>Forensic</strong> SATA/IDE Bridge IEEE 1394 SBP2<br />

Device<br />

Source hashes<br />

md5: 5781d0f597685d4eff4cc3423900d73a<br />

sha1: e878400c062b1690b586be41523d303edf3eae52<br />

/dev/sda: current max LBA: 156,301,488<br />

/dev/sda: native max LBA: 156,301,488<br />

/dev/sda: physical max LBA: 156,301,488<br />

/dev/sda: HPA not set<br />

/dev/sda: DCO not set<br />

Device Start End #sectors File System Size<br />

/dev/sdb1 4096 4198399 4194304 HFS 2Gb<br />

/dev/sdb2 4198400 14999551 10801152 HFS+ 5Gb<br />

Unallocated<br />

Start DC3DD (md5 sha1): Fri Oct 1 10:11:33 NZDT 2010<br />

command line: dc3dd hash=md5,sha1 hashlog=/tmp/hash.log<br />

status=noxfer if=/dev/sda3 skip=0 conv=noerror,sync iflag=direct<br />

ibs=32768<br />

compiled options: DEFAULT_BLOCKSIZE=32768<br />

sector size: 512 (assumed)<br />

md5 TOTAL: 5781d0f597685d4eff4cc3423900d73a<br />

267

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!