30.06.2013 Views

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Partition<br />

Table:<br />

Log<br />

highlights:<br />

Results by<br />

assertion:<br />

AIR 2.0.0 (Release Date: 17th, Feb 2010)<br />

/dev/sdb: current max LBA: 156,301,488<br />

/dev/sdb: native max LBA: 156,301,488<br />

/dev/sdb: physical max LBA: 156,301,488<br />

/dev/sdb: HPA and DCO are not set<br />

Device Start End #sectors System<br />

/dev/sdb1 63 2104514 2104452 FAT32<br />

/dev/sdb2 2104515 6297479 4192965 NTFS<br />

/dev/sdb3 6297480 156296384 149998905 NTFS<br />

Start DC3DD (md5 sha1): Sun Oct 17 16:32:52 NZDT 2010<br />

Hash will be calculated on port:5058.<br />

command line: dc3dd hash=md5,sha1 hashlog=/tmp/hash.log status=noxfer<br />

<strong>of</strong>=/root/AIR_Network seek=0 obs=32768<br />

compiled options: DEFAULT_BLOCKSIZE=32768<br />

md5 TOTAL: 14d2c1027467bc11c8405c0ff961f2e4<br />

sha1 TOTAL: 583d77bf05a1b12600eaa4100b740459dda34308<br />

2104452+0 sectors in<br />

2104452+0 sectors out<br />

Command completed: Sun Oct 17 16:36:23 NZDT 2010<br />

Start VERIFY: Sun Oct 17 16:36:23 NZDT 2010<br />

Command-line: dc3dd if=/root/AIR_Network hash=md5,sha1<br />

conv=noerror,sync hashlog=/tmp/verify_hash.log status=noxfer | air-counter<br />

2>> /usr/local/share/air/logs/air.buffer.data > /dev/null<br />

VERIFY SUCCESSFUL: Hashes match<br />

Orig = md5 TOTAL: 14d2c1027467bc11c8405c0ff961f2e4<br />

sha1 TOTAL: 583d77bf05a1b12600eaa4100b740459dda34308<br />

Copy = md5 TOTAL: 14d2c1027467bc11c8405c0ff961f2e4<br />

sha1 TOTAL: 583d77bf05a1b12600eaa4100b740459dda34308<br />

Command completed: Sun Oct 17 16:36:44 NZDT<br />

AFR-01 PASSED AIC-01 PASSED ALOG-01 PASSED<br />

AFR-02 PASSED AIC-02 PASSED ALOG-02 PASSED<br />

AFR-03 PASSED AIC-05 PASSED ALOG-03 PASSED<br />

AFR-04 PASSED AIC-06 PASSED<br />

AFR-05 PASSED AIC-07 PASSED<br />

AFR-07 PASSED AIC-08 PASSED<br />

Analysis: Test achieved expected result.<br />

292

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!