30.06.2013 Views

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Source<br />

Device:<br />

Drive<br />

Setup:<br />

Partition<br />

Table<br />

(GPT<br />

disk):<br />

Log<br />

highlights:<br />

AIR 2.0.0 (Release Date: 17th, Feb 2010)<br />

02 in<strong>for</strong>mation about the acquisition at least including following: device, start<br />

sector, end sector, type and number <strong>of</strong> errors encountered, and start time and<br />

ALOG-<br />

03<br />

end time <strong>of</strong> acquisition.<br />

The tool display correct in<strong>for</strong>mation regarding to the acquisition to the user<br />

and the in<strong>for</strong>mation displayed is consistent with the log file if the log file<br />

function is supported<br />

AHS-01 The tool reports to the user if any hidden sectors are found<br />

AHS-02<br />

AHS-03<br />

The tool reports to the user that digital source may contain hidden sector but<br />

undetected if the tool is unable to determine whether hidden sectors are<br />

present due to incompatible execution environment<br />

The tool reports to the user that hidden sectors will not be acquired if the tool<br />

is unable to acquire hidden sectors due to incompatible execution<br />

environment<br />

Drive Model: ST380817AS (80GB)<br />

Serial Number: 5MR18V18<br />

Sector count: 156,301,488<br />

Write blocker: N/A<br />

/dev/sdb: current max LBA: 156,301,488<br />

/dev/sdb: native max LBA: 156,301,488<br />

/dev/sdb: physical max LBA: 156,301,488<br />

/dev/sdb: HPA set from sector 6,500,001 to 156,301,487 (Total<br />

149,801,488 sectors are hidden)<br />

Device Start End #sectors File System<br />

/dev/sdb1 2048 4198399 4196352 FAT32<br />

/dev/sdb2 4198400 6297599 2099200 EXT4<br />

/dev/sdb3 6301488 156305199 150003712 NTFS (Partially<br />

290<br />

HPA)<br />

Start DC3DD (md5 sha1): Mon Oct 18 05:48:27 NZDT 2010<br />

command line: dc3dd hash=md5,sha1 hashlog=/tmp/hash.log status=noxfer<br />

if=/dev/sda skip=0 conv=noerror,sync iflag=direct ibs=32768<br />

compiled options: DEFAULT_BLOCKSIZE=32768<br />

md5 TOTAL: 66b09a0f6194157cbd492b16c58e9900<br />

sha1 TOTAL: cab5ec0c50fd232bcce40fa71deaaeb83b7af675<br />

6500000+0 sectors in<br />

6500000+0 sectors out<br />

Command completed: Mon Oct 18 05:51:00 NZDT 2010<br />

Start VERIFY: Mon Oct 18 05:51:00 NZDT 2010<br />

Command-line: cat /mnt/new/AIR_GPThpa.* | air-counter 2>><br />

/usr/local/share/air/logs/air.buffer.data | dc3dd hash=md5,sha1<br />

hashlog=/tmp/verify_hash.log status=noxfer <strong>of</strong>=/dev/null<br />

VERIFY SUCCESSFUL: Hashes match<br />

Orig = md5 TOTAL: 66b09a0f6194157cbd492b16c58e9900<br />

sha1 TOTAL: cab5ec0c50fd232bcce40fa71deaaeb83b7af675<br />

Copy = md5 TOTAL: 66b09a0f6194157cbd492b16c58e9900<br />

sha1 TOTAL: cab5ec0c50fd232bcce40fa71deaaeb83b7af675<br />

Command completed: Mon Oct 18 05:53:36 NZDT 2010

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!