Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 28 guests and 2 members online
 
Free Business and Tech Magazines and eBooks

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Forensicsarrow Forensic write blockers
EH-Net
May 24, 2013, 06:29:31 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Forensic write blockers  (Read 11075 times)
0 Members and 1 Guest are viewing this topic.
jimbob
Guest
« on: June 13, 2007, 02:32:46 AM »

Hi,
I am interested in getting a forensic write blocked (FireWire/USB 2.0), does anyone have any recommendations? I don't want to spend a huge amount of money and some of the solutions run into hundreds of dollarpounds. Are there any 'budget' options that would be considered forensically sound?

Jim
Logged
warquel
Newbie
*
Offline Offline

Posts: 5


View Profile
« Reply #1 on: July 05, 2007, 12:28:52 AM »

It really depends on what you're capturing. PATA? SATA? SCSI (I/II/III)? SCA? 1.8" IDE, 2.5" IDE? USB? Flash? SD? When you get down to it there's no cheap solution. You're likely to spend a lot just to cover the bases.

If you really need to budget then review what your most likely acquisitions are going to be. If you have a lot of legacy systems, it'll likely be IDE. Newer systems, SATA. High Availability servers? SCSI. Then price out one and figure something out for the others.

Some nice little devices that we use are the FireFly (SATA->Firewire) hardware write blocks. They're around US$200. You can find them here http://www.digitalintelligence.com/forensicwriteblockers.php along with other forensic write blockers.

If you want to go the cheapest route, use a linux system with auto mounting disabled and buy some USB or Firewire drive enclosures. If you go this route make sure you create a documented procedure for acquiring evidence and follow it every time. You might even go as far as to record the history of your shell commands as part of your digital case file.
Logged
jimbob
Guest
« Reply #2 on: July 05, 2007, 03:51:01 AM »

Thanks for the excellent response. I am going to go down the route of using Helix, a well documented procedure and a detailed record of the actions taken to acquire the image. I will purchase hardware blockers only if I get a case may go to court and/or the customer is willing to pay extra for the added security.

Regards,
Jim
Logged
oleDB
Recruiters
Full Member
*
Offline Offline

Posts: 236



View Profile WWW
« Reply #3 on: July 05, 2007, 02:26:43 PM »

Not positive on this but I think you can remove the connector for pin23 on your cable and make your own write blocker.

http://en.wikipedia.org/wiki/AT_Attachment

Anyone ever attempt this?
Logged
dalepearson
Sr. Member
****
Offline Offline

Posts: 357


View Profile WWW
« Reply #4 on: July 10, 2007, 05:24:42 AM »

I have been using an IDE FastBlock from Guardian up till now, but its been messing around. So I am upgrading the lot and have gone for a Tableau T35i Forensic SATA/IDE Bridge. Should arrive this week hopefully.

Logged

Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.06 seconds with 22 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.