Notifications
Clear all

DD and FTK

18 Posts
5 Users
0 Likes
3,242 Views
hogfly
(@hogfly)
Posts: 287
Reputable Member
Topic starter
 

I wasn't quite sure where to post this…

I'm using FTK and trying to mount an EXT3 partition containing a dd image of an NTFS partition. I can mount the physical disk as evidence and can search the dd image just fine. What I was wondering is if anyone knows of a way to mount the dd image so I can get a filelisting rather than viewing it as raw data.

Any help is appreciated.

 
Posted : 19/08/2005 8:18 am
(@nbeattie)
Posts: 26
Eminent Member
 

Hogfly

Have you added the DD image as evidence in FTK ?

Neil Beattie

 
Posted : 19/08/2005 1:06 pm
nickfx
(@nickfx)
Posts: 131
Estimable Member
 

If you use FTK Imager you can 'mount' the dd image in a file list view. You can browse folders and files in an explorer type view.

Nick

 
Posted : 19/08/2005 2:23 pm
hogfly
(@hogfly)
Posts: 287
Reputable Member
Topic starter
 

ok, excuse my ignorance of commercial tools, but how exactly does one mount a dd image on an ext3 partition as evidence when FTK only allows me to mount the disk containing the ext3 partition as the 'physical disk' since windows can't natively mount a logical partition that is ext3? I can see the dd image and view the contents in hex or ascii, but can't do a file listing.

Thanks.

 
Posted : 19/08/2005 5:37 pm
 Andy
(@andy)
Posts: 357
Reputable Member
 

Xtract the DD image files from the FTK case (to a folder on your local machine). Then import this as evidence into this or another case……. Should work a treat. FTK handles DD images no problem.

Andy

 
Posted : 19/08/2005 5:43 pm
(@nbeattie)
Posts: 26
Eminent Member
 

I have experimented in the past with booting into Helix then using DD to create an image on an attached USB drive that has an ext2 partition.

Then using a utility called ext2fs, I was able to mount the drive in Windows. I didn't find the performance to be adequate, so I copied the DD file onto the local hard disk and worked with the image from there.

Doing a quick search on the net, there are a number of utilities that will allow you to mount an ext3 partition in Windows. For example, http//uranus.it.swin.edu.au/~jn/linux/ext2ifs.htm

Don't know how well they work as I've only used ext2fs but worth looking into.

Neil

 
Posted : 19/08/2005 5:54 pm
hogfly
(@hogfly)
Posts: 287
Reputable Member
Topic starter
 

Andy,
That's what I was considering. Using that method requires a write blocker, does it not?
nbeattie mount-everything was reccommended to me for just that purpose, except it's not forensically sound.
Thanks for the help.

 
Posted : 19/08/2005 6:22 pm
nickfx
(@nickfx)
Posts: 131
Estimable Member
 

Dont excuse your ignorance, I didnt read your question properly, Andy helped clarify though.

Cheers

Nick

 
Posted : 19/08/2005 6:31 pm
(@nbeattie)
Posts: 26
Eminent Member
 

I'm intrigued as to what you consider to be "not forensically sound" ?

 
Posted : 19/08/2005 6:48 pm
 Andy
(@andy)
Posts: 357
Reputable Member
 

hogfly, if you have accessed the drive as a physical device in FTK without a write blocker then it has not been handled in a forensically sound manner, i.e. you have accessed the original data. So it is a bit late to worry about a write blocker; however the DD image you have on the suspect drive is in effect a 'container' with a file system locked within. By making and using copies, you will always have the original DD files - untouched…. well almost, as you will have possibly altered the original DD files (at least their attributes - last accessed) by mounting them in FTK as a physical device without a write blocker.

Andy

P.S. If you need a write blocker you can try Data Duplication http//www.dataduplication.co.uk/. Their web site is awful, but the products aren't bad.

 
Posted : 19/08/2005 7:36 pm
Page 1 / 2
Share: