DVR image (linux) u...
 
Notifications
Clear all

DVR image (linux) unsupported by forensic software

6 Posts
4 Users
0 Reactions
563 Views
CopyRight
(@copyright)
Estimable Member
Joined: 13 years ago
Posts: 184
Topic starter  

I am currently working with a dvr i have retrieved, inside it a 2 TB seagate hard drive, after i've taken an image of it and opened it using FTK it show me 3 partitions, one NTFS which only has logs and 2 others are LINUX (un-allocated space) and it has a lot of data!

How can i read that LINUX (un-allocated space data )


   
Quote
(@mscotgrove)
Prominent Member
Joined: 17 years ago
Posts: 940
 

Have you tried carving the 'Linux' to see if there recognisable file types?


   
ReplyQuote
jhup
 jhup
(@jhup)
Noble Member
Joined: 16 years ago
Posts: 1442
 

Can we get a bit of clarification?
Linux is an operating system.

What file systems are on the non-NTFS partitions?

With more details we can help you narrow it down.

I am currently working with a dvr i have retrieved, inside it a 2 TB seagate hard drive, after i've taken an image of it and opened it using FTK it show me 3 partitions, one NTFS which only has logs and 2 others are LINUX (un-allocated space) and it has a lot of data!

How can i read that LINUX (un-allocated space data )


   
ReplyQuote
CopyRight
(@copyright)
Estimable Member
Joined: 13 years ago
Posts: 184
Topic starter  

One partition said NTFS and the other one said (Linux Native).. soomehow when we mounted it in out forensic workstation nothing has appeared however in the disk manamgnet it shows that the paritition holds an EXT2 partition.


   
ReplyQuote
HexDrugsRockNRoll
(@hexdrugsrocknroll)
Trusted Member
Joined: 17 years ago
Posts: 60
 

Have you tried viewing the partition table using 'parted' in Linux?


   
ReplyQuote
jhup
 jhup
(@jhup)
Noble Member
Joined: 16 years ago
Posts: 1442
 

What version of FTK are you using? More recent versions support ext2 and ext3 without a problem.

An alternate way of getting to see the ext2 partitions is to get ext2Read installed. It is a FOSS piece that will allow you to view ext2, ext3 and ext4.


   
ReplyQuote
Share: