30.06.2013 Views

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Partition<br />

Table:<br />

Log<br />

highlights:<br />

Results by<br />

assertion:<br />

AIR 2.0.0 (Release Date: 17th, Feb 2010)<br />

Device Start End #sectors File System<br />

/dev/sdb1 2048 40962047 40960000 NTFS<br />

/dev/sdb2 40962048 83970047 43008000 Ext4<br />

/dev/sdb3 83972096 156350047 72377951 Extended<br />

(Modified)<br />

Start DC3DD (md5 sha1): Fri Sep 10 05:02:41 NZST 2010<br />

command line: dc3dd hash=md5,sha1 hashlog=/tmp/hash.log<br />

status=noxfer if=/dev/sdc skip=0 conv=noerror,sync iflag=direct<br />

ibs=32768<br />

sector size: 512 (assumed)<br />

md5 TOTAL: b42f526d394078656308a9b96aa77188<br />

sha1 TOTAL: e2977a0cd2d2608519b1750e980252d01cdb4718<br />

156301488+0 sectors in<br />

156301488+0 sectors out<br />

Command completed: Fri Sep 10 06:31:40 NZST 2010<br />

Start VERIFY: Fri Sep 10 06:31:40 NZST 2010<br />

Command-line: cat /mnt/new/Image/PartitionOutOfBound.* | air-counter<br />

2>> /usr/local/share/air/logs/air.buffer.data | dc3dd hash=md5,sha1<br />

hashlog=/tmp/verify_hash.log status=noxfer <strong>of</strong>=/dev/null<br />

VERIFY SUCCESSFUL: Hashes match<br />

Orig = md5 TOTAL: b42f526d394078656308a9b96aa77188<br />

sha1 TOTAL: e2977a0cd2d2608519b1750e980252d01cdb4718<br />

Copy = md5 TOTAL: b42f526d394078656308a9b96aa77188<br />

sha1 TOTAL: e2977a0cd2d2608519b1750e980252d01cdb4718<br />

Command completed: Fri Sep 10 07:31:37 NZST 2010<br />

AFR-01 PASSED AIC-01 PASSED<br />

AFR-02 PASSED AIC-02 PASSED<br />

AFR-03 PASSED AIC-11 FAILED<br />

AFR-04 PASSED ALOG-01 PASSED<br />

AFR-05 PASSED ALOG-02 PASSED<br />

AFR-07 PASSED ALOG-03 PASSED<br />

Analysis: Test FAILED to achieve the expected Result. AIR fails to report to the<br />

user that irregularities in the digital source.<br />

3.19. TC-15 Unreadable MBR<br />

Test Case TC-15 Unreadable MBR (AIR 2.0.0)<br />

Test &<br />

Case<br />

Summary:<br />

Acquire a hard disk with an unreadable MBR<br />

Notes: Partitions ended out <strong>of</strong> the physical boundary <strong>of</strong> the disk. <strong>Data</strong> <strong>of</strong> MBR is replaced<br />

by value 0.<br />

Assertions: AFR-01 The tool accesses the digital source with a supported access interface<br />

AFR-02 The tool acquires a digital source<br />

AFR-03 The tool operates in an execution environment<br />

AFR-04 The tool creates an image file <strong>of</strong> the digital source<br />

AFR-05 The tool acquires all the visible data sectors from the digital source<br />

AFR-07 All data sectors acquired from the digital source are acquired accurately.<br />

AFR-08 The tool reports to the user <strong>of</strong> the error type and the location <strong>of</strong> the error if<br />

284

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!