30.06.2013 Views

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Drive<br />

Setup:<br />

Partition<br />

Table:<br />

Log<br />

highlights:<br />

AIR 2.0.0 (Release Date: 17th, Feb 2010)<br />

Sector count: 156,301,488<br />

Write blocker: N/A<br />

Source hashes<br />

MD5 checksum: 69fdef5d5de3a207bc2a04017c38c3fd<br />

SHA1 checksum: 9d768ab184ed9a172031f0f7b7f721f2bdf80b59<br />

/dev/sdb: current max LBA: 94,863,828<br />

/dev/sdb: native max LBA: 94,863,828<br />

/dev/sdb: physical max LBA: 156,301,488<br />

/dev/sdb: HPA not set<br />

/dev/sdb: DCO set from sector 94,863,828 to 156,301,487<br />

Device Start End #sectors File System<br />

/dev/sdb1 63 41945714 41945652 NTFS<br />

/dev/sdb2 41945715 94863824 52918110 Ext3<br />

/dev/sdb3 94863825 156296384 61432560 NTFS<br />

271<br />

(DCO)<br />

Start DC3DD (md5 sha512): Mon Jul 26 02:57:13 NZST 2010<br />

dc3dd 6.12.4 started at 2010-07-26 02:57:13 +1200<br />

command line: dc3dd hash=md5,sha512 hashlog=/tmp/hash.log status=noxfer<br />

if=/dev/sda skip=0 conv=noerror iflag=direct ibs=32768<br />

compiled options: DEFAULT_BLOCKSIZE=32768<br />

sector size: 512 (assumed)<br />

md5 TOTAL: 69fdef5d5de3a207bc2a04017c38c3fd<br />

sha512 TOTAL:<br />

4ad5009bfc6232521fd893ad7d8cc7e0d592aa5de8cb6904b8d189664656ec517<br />

cc0e31fb57a93d034a3c23498c1494d54e2488835c2b6c3588b3607af48ad5f<br />

94868928+0 sectors in<br />

94868928+0 sectors out<br />

dc3dd completed at 2010-07-26 04:16:50 +1200<br />

Command completed: Mon Jul 26 04:16:53 NZST 2010<br />

Start VERIFY: Mon Jul 26 04:16:53 NZST 2010<br />

Command-line: cat /mnt/dconew/new/ST380817AS_DCO_94868928.* | aircounter<br />

2>> /usr/local/share/air/logs/air.buffer.data | dc3dd hash=md5,sha512<br />

hashlog=/tmp/verify_hash.log status=noxfer <strong>of</strong>=/dev/null<br />

VERIFY SUCCESSFUL: Hashes match<br />

Orig = md5 TOTAL: 69fdef5d5de3a207bc2a04017c38c3fd<br />

sha512 TOTAL:<br />

4ad5009bfc6232521fd893ad7d8cc7e0d592aa5de8cb6904b8d189664656ec517<br />

cc0e31fb57a93d034a3c23498c1494d54e2488835c2b6c3588b3607af48ad5f<br />

Copy = md5 TOTAL: 69fdef5d5de3a207bc2a04017c38c3fd<br />

sha512 TOTAL:<br />

4ad5009bfc6232521fd893ad7d8cc7e0d592aa5de8cb6904b8d189664656ec517<br />

cc0e31fb57a93d034a3c23498c1494d54e2488835c2b6c3588b3607af48ad5f<br />

Command completed: Mon Jul 26 05:50:14 NZST 2010

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!