Hello everybody,
Does anybody know a free tool which can be used to calculate the hash of a disk in Windows (for example, a CD-ROM, a DVD or a pen drive connected in read only mode? The most of the free tools you can find on the net only calculate hashes for single files but not hashes for complete drives.
Thank you in advance!
Hello everybody,
Does anybody know a free tool which can be used to calculate the hash of a disk in Windows (for example, a CD-ROM, a DVD or a pen drive connected in read only mode? The most of the free tools you can find on the net only calculate hashes for single files but not hashes for complete drives.
Thank you in advance!
You can use dsfo (DSFOK toolkit) outputting to NUL to get the MD5
http//
Like
dsfo \\.\Physicaldriven 0 0 NUL
jaclaz
Hello everybody,
Does anybody know a free tool which can be used to calculate the hash of a disk in Windows (for example, a CD-ROM, a DVD or a pen drive connected in read only mode? The most of the free tools you can find on the net only calculate hashes for single files but not hashes for complete drives.
Thank you in advance!
You can use dsfo (DSFOK toolkit) outputting to NUL to get the MD5
http//members.ozemail.com.au/~nulifetv/freezip/freeware/
Like
dsfo \\.\Physicaldriven 0 0 NULjaclaz
Thanks jaclaz. I don't understand the command line you wrote. Do you mean I have to open a DOS console in the folder in which dsfo tool is located and execute that line? I have downloaded the tool but it only accepts 4 GB files, is it correct?
Anyway, MD5 has collisions…
Thanks!
Anyway, MD% has collisions…
Thanks!
But are they relevant - what are you trying to achieve?
Does anybody know a free tool which can be used to calculate the hash of a disk in Windows (for example, a CD-ROM, a DVD or a pen drive connected in read only mode?
As far as I know OSForensics from PassMark does that for free http//
Avoiding the Pandora's Box you've opened regarding MD5 for a moment..
EnCase Acquision v6 will allow you to add a local device then hash it "in place", if that's what you want. Just add the device to a case and right-click "Hash..". You can do SHA1 or MD5
FTK Imager v3 also lets you do this - add an evidence item then right-click and choose "Verify". Again, it gives you the SHA1 if MD5 upsets you.
I think they're both free, although you might have to register first.
Thanks jaclaz. I don't understand the command line you wrote. Do you mean I have to open a DOS console in the folder in which dsfo tool is located and execute that line?
Yep, or put the executable in a directory belonging to PATH.
I have downloaded the tool but it only accepts 4 GB files, is it correct?
Not that I know of, from where/how did you get this?
Anyway, MD% has collisions…
Sure ) , now be nice and do the math of the probability that a copy/transfer of data can create accidentally a collision.
A hash is not usually a verification of integrity of data, it is a form of verification that no (accidental) copy/transfer error happened
http//www.forensicfocus.com/Forums/viewtopic/t=13328/
@raydenvm
Seemingly the OSforensics creates hashes for files and volumes (not "whole" disks) ?
http//
jaclaz
Does anybody know a free tool which can be used to calculate the hash of a disk in Windows (for example, a CD-ROM, a DVD or a pen drive connected in read only mode?
As far as I know OSForensics from PassMark does that for free http//
www.osforensics.com/osforensics.html
Hello. Thanks for your answer.
I've tried to use OSForensic but it doesn't allow you to calculate the hash of a CD-ROM or DVD, it only calculates the hashes of partitions of the hard drives connected to the motherboard.
Thanks jaclaz. I don't understand the command line you wrote. Do you mean I have to open a DOS console in the folder in which dsfo tool is located and execute that line?
Yep, or put the executable in a directory belonging to PATH.
I have downloaded the tool but it only accepts 4 GB files, is it correct?
Not that I know of, from where/how did you get this?
Anyway, MD% has collisions…
Sure ) , now be nice and do the math of the probability that a copy/transfer of data can create accidentally a collision.
A hash is not usually a verification of integrity of data, it is a form of verification that no (accidental) copy/transfer error happened
http//www.forensicfocus.com/Forums/viewtopic/t=13328/@raydenvm
Seemingly the OSforensics creates hashes for files and volumes (not "whole" disks) ?
http//www.osforensics.com/verify-and-match-files.html jaclaz
Hello,
I took the tool from the repository you posted.
path dsfok\dsfok\GUI\dsfo.exe
If I open a DOS shell and I execute "dsfo.exe" with your command, it only launches the programm in its windows environment, but doesn't do anything else.
Regards!
Hello,
I took the tool from the repository you posted.
path dsfok\dsfok\GUI\dsfo.exe
If I open a DOS shell and I execute "dsfo.exe" with your command, it only launches the programm in its windows environment, but doesn't do anything else.
Regards!
Get the command line version, which is in the "root" of the archive, NOT the one in the \GUI\ folder.
(the one in the GUI folder is only a - simplified - GUI interface to the command line one)
As a side note, to be picky (as I am), in Windows NT you are not running a DOS shell when you open a command prompt or console, you are running the NT command interpreter CMD.EXE.
jaclaz