Forensic Focus - Computer Forensics, Computer Forensic Training, Digital Forensics
LoginRegisterForumsColumnistsPapersEducationGraduatesReviewsInterviewsNewsletterJobsEventsBlogAdvertise
Search Forensic Focus
Custom Search

Find us on Facebook
Follow Forensic Focus on Twitter
Columnists
"I erred." "I was mistaken."
Craig Ball
Single Sign On
Simon Biles
Copyright and games console modification
Dan Gaskell
To GUI or not to GUI?
Chris Hargreaves
'Web 2.0' as evidence
Sean McLinden
Sometimes it’s all about timing
Sam Raincock
Avoiding common job application errors
David Sullivan
Scalability: A Big Headache
Dominik Weber
Graduate Recruitment

computer forensics graduate jobs

Main Menu
MY ACCOUNT
COMMUNITY
EMPLOYMENT
EDUCATION
RESOURCES
MISC
Follow Forensic Focus

Join newsletter

Join LinkedIn group

Follow on Twitter

Subscribe to news

Subscribe to forums

Subscribe to blog

Subscribe to tweets

Members' blogs

External feeds

Bookmark & share: Bookmark and Share

Computer Forensics Newsletter
Newsletter

You must be a
registered user
to receive our newsletter

Register Now!

fdisk on a Windows image
Post new topic   Reply to topic   Printer Friendly Page     Forum Index -> General Discussion
View previous topic :: View next topic  
Author Message
jaclaz
Senior Member


Joined: Nov 16, 2007
Posts: 420
Location: Near Florence - Italy

PostPosted: Sun Dec 21, 2008 7:04 am    Post subject: Re: fdisk on a Windows image Reply with quote

kleanchap wrote:
Thank you for explaining this!

What tools should I use against partition images to get the partition layout? I am looking for files, directories and their metadata.

K

Why don't you mount the image file?

And then use "normal" filesystem tools?

Or (for some data) you may want to use TESTDISK:
www.cgsecurity.org/wiki/TestDisk

Or you may want to use some Forensic utilities....
www.sleuthkit.org/

Read related tutorials articles:
www.forensicfocus.com/...lysis-ntfs

In other words:
WHAT EXACTLY are you trying to do/WHAT EXACT data you need to retrieve/look at?

Then, after having read and understood the basics of the filesystems/partitioning, etc., you could ask specific questions about something that you still have not clear.

A tool is, well, a tool, nothing more, it is the knowledge, the skill and experience of the user of the tool that makes it useful. Wink

Don't take it the wrong way, but it seems to me like you asked:
Quote::
What do I use to shorten a wooden plank?

To which anyone can answer ANY of the following:
a saw
a hacksaw
a circular saw
a band saw
a jig saw
an axe
a hatchet

They are all valid answers, but each of them has it's own advantages and drawbacks, there may be a "better" answer among them for your particular case.

And however, using the "right" tool does not guarantee that the wooden plank will be shortened to the right measure and with a clean cut if you don't know how to use the tool properly....

jaclaz
Back to top
View user's profile
farmerdude
Senior Member


Joined: Jan 13, 2006
Posts: 231
Location: USA

PostPosted: Mon Jan 05, 2009 8:35 am    Post subject: Re: fdisk on a Windows image Reply with quote

kleanchap,

If you want to dump file system meta data and file metadata and data then you would call upon file system and file tools. The NTFSPROGS package has a number of file system metadata tools. Various forensics applications do as well.

You could use a mount tool such as SMART MOUNT to mount the file system image and then your normal operating system environment to analyze the data.

Cheers!

farmerdude


www.forensicbootcd.com

www.onlineforensictraining.com
Back to top
View user's profile
mscotgrove
Senior Member


Joined: Jan 01, 2009
Posts: 235
Location: Sussex, UK

PostPosted: Mon Jan 05, 2009 9:42 am    Post subject: Re: fdisk on a Windows image Reply with quote

Some more ideas - that I often refer to

www.win.tue.nl/~aeb/pa...pes-1.html



Also have a look at the start of the partition, can often indicate what it is
Back to top
View user's profile Visit poster's website
Spawn
Newbie


Joined: May 11, 2008
Posts: 21
Location: UK

PostPosted: Tue Jan 06, 2009 5:47 am    Post subject: Re: fdisk on a Windows image Reply with quote

Just a suggestion but you might get more assistance if you posted the hex from the start of the image rather than the ouput from some tool.
Back to top
View user's profile
Display posts from previous:   
Post new topic   Reply to topic   Printer Friendly Page     Forum Index -> General Discussion All times are GMT - 6 Hours
Page 1 of 1


Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


Use of this website signifies your agreement to the Terms of Use/Privacy Policy available here.

All logos and trademarks in this site are property of their respective owner. The comments are property of their posters, all the rest © 2010 Forensic Focus


Interactive software released under GNU GPL, Code Credits, Privacy Policy
.: fisubsilver shadow phpbb2 style by Daz :: CPG-Nuke port by norseman :: ported to CPG-Dragonfly by jamin :.