30.06.2013 Views

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Source<br />

Device:<br />

Drive<br />

Setup:<br />

Partition<br />

Table:<br />

Log<br />

highlights:<br />

Results by<br />

assertion:<br />

AIR 2.0.0 (Release Date: 17th, Feb 2010)<br />

AHS-02 The tool reports to the user that digital source may contain hidden sector but<br />

undetected if the tool is unable to determine whether hidden sectors are<br />

present due to incompatible execution environment<br />

AHS-03 The tool reports to the user that hidden sectors will not be acquired if the tool<br />

is unable to acquire hidden sectors due to incompatible execution<br />

environment<br />

Drive Model: ST380817AS (80GB)<br />

Serial Number: 5MR18V18<br />

Sector count: 156,301,488<br />

Write blocker: N/A<br />

/dev/sdb: current max LBA: 149,565,150<br />

/dev/sdb: native max LBA: 149,565,150<br />

/dev/sdb: physical max LBA: 156,301,488<br />

/dev/sdb: HPA set from sector 149,565,150 to 156,301,487 (Total<br />

6,736,337 sectors)<br />

Device Start End #sectors File System<br />

/dev/sdb1 63 2104514 2104452 NTFS<br />

/dev/sdb2 2104515 149565149 145460535 Ext3<br />

/dev/sdb3 149565150 156296384 6731234 FAT32 (Entire<br />

HPA)<br />

Start DC3DD (md5 sha1): Wed Sep 1 02:36:13 NZST 2010<br />

dc3dd hash=md5,sha1 hashlog=/tmp/hash.log status=noxfer if=/dev/sda3<br />

skip=0 conv=noerror,sync iflag=direct ibs=32768 2>><br />

/usr/local/share/air/logs/air.image.log | air-counter 2>><br />

/usr/local/share/air/logs/air.buffer.data | /usr/local/bin/split -a 3 -d -b 2047m -<br />

/mnt/new/Image/partition_whole_HPA. >><br />

/usr/local/share/air/logs/air.image.log 2>&1<br />

dc3dd: opening `/dev/sda3': No such file or directory<br />

Command completed: Wed Sep 1 02:36:16 NZST 2010<br />

Start VERIFY: Wed Sep 1 02:36:16 NZST 2010<br />

Command-line: cat /mnt/new/Image/partition_whole_HPA.* | air-counter<br />

2>> /usr/local/share/air/logs/air.buffer.data | dc3dd hash=md5,sha1<br />

hashlog=/tmp/verify_hash.log status=noxfer <strong>of</strong>=/dev/null<br />

VERIFY FAILED: Hashes don't match<br />

Orig =<br />

Copy = md5 TOTAL: d41d8cd98f00b204e9800998ecf8427e<br />

sha1 TOTAL: da39a3ee5e6b4b0d3255bfef95601890afd80709<br />

Command completed: Wed Sep 1 02:36:19 NZST 2010<br />

AFR-01 PASSED AIC-01 PASSED AHS-02 FAILED<br />

AFR-02 PASSED AIC-02 PASSED AHS-03 FAILED<br />

AFR-03 PASSED AIC-05 PASSED ALOG-01 PASSED<br />

AFR-04 PASSED AIC-06 PASSED ALOG-02 PASSED<br />

AFR-05 PASSED AIC-07 PASSED ALOG-03 PASSED<br />

AFR-06 FAILED AIC-08 PASSED<br />

AFR-07 PASSED AHS-01 FAILED<br />

Analysis: Test FAILED to achieve the expected Result. AIR failed to detect and<br />

acquire the hidden areas in the hard drive. AIR stopped immediately when<br />

attempting to acquire the hidden partition and indicated no such file or<br />

directory in the partition.<br />

281

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!