Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 48 guests online
 
Free Business and Tech Magazines and eBooks

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Forensicsarrow tools for hard drive duplication
EH-Net
May 18, 2013, 03:49:03 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: tools for hard drive duplication  (Read 5257 times)
0 Members and 1 Guest are viewing this topic.
jason.williams14
Newbie
*
Offline Offline

Posts: 2


View Profile
« on: May 09, 2009, 01:31:20 PM »

hello everyone.

I am looking for some information and tools that will help with hard drive duplication for forensic work. This would be for Windows, Linux, Mac as well as UNIX.

Is there one specific tool that can be used for all of these OS's? Or is there one best suited for each O?

I am familiar with Norton Ghost, but since the world of forensics in computer is very delicate and not tampering with the data is critical, I was looking for options and solutions for hard drive duplication.

Anyone recommend any tools?

Much obliged.

J.
Logged
TTewell
Newbie
*
Offline Offline

Posts: 21


View Profile
« Reply #1 on: May 09, 2009, 04:03:22 PM »

2 letters.  DD      Grin
Logged
Ketchup
Hero Member
*****
Offline Offline

Posts: 1021



View Profile
« Reply #2 on: May 09, 2009, 04:46:01 PM »

Yep, DD, DCFLDD is even  better.   I would look into the Raptor forensics boot disc, as well as Helix.   Raptor is much easier to use for one that doesn't have Linux experience.    Helix is more powerful.
Logged

~~~~~~~~~~~~~~
Ketchup
Otter
Newbie
*
Offline Offline

Posts: 41


View Profile
« Reply #3 on: May 10, 2009, 01:27:02 AM »

hello everyone.

I am looking for some information and tools that will help with hard drive duplication for forensic work. This would be for Windows, Linux, Mac as well as UNIX.

Is there one specific tool that can be used for all of these OS's? Or is there one best suited for each O?

I am familiar with Norton Ghost, but since the world of forensics in computer is very delicate and not tampering with the data is critical, I was looking for options and solutions for hard drive duplication.

Anyone recommend any tools?

Much obliged.

J.

A book written by a buddy of mine may be something you'd enjoy:

http://www.amazon.com/UNIX-Linux-Forensic-Analysis-Toolkit/dp/1597492698/ref=sr_1_1?ie=UTF8&s=books&qid=1241936083&sr=1-1

It mentions ddfl-dd (dd that also cuts md5 on the fly),  EnCase's LinEn, Access Data's FTK Imager, and ProDiscover as options for imaging.   Encase forensic edition apparently remains the pro's choice but does cost a lot more than "free."   

You may be interested in the Helix distro of Linux, but I think they may have gone non-free here very recently:
http://distrowatch.com/?newsid=05102

Whatever you use, what's most important is to make certain that your image includes all slack space, and can be verified (via md5 or shasums) to be identical to the original disk, chain of custody maintained, preferably image taken with write wires cut, and all that good forensics guy doo dah stuff!



Logged
jason.williams14
Newbie
*
Offline Offline

Posts: 2


View Profile
« Reply #4 on: May 10, 2009, 04:26:57 PM »

Thanks guys. I really appreciate it.

Ya, I was thinking of DD with a combo of netcat. That would work.
I will try the other one, dflcdd...seems cool.

EnCase seems to be very popular product. I should look into it further.

Thanks!
Logged
Ketchup
Hero Member
*****
Offline Offline

Posts: 1021



View Profile
« Reply #5 on: May 10, 2009, 04:29:37 PM »

There are very few people actually doing imaging with EnCase products, including Linen.   They are painfully slow.   The Raptor disc is able to create E01 images, much much faster than EnCase or Linen can.   We get about 2 GB/min on decent hardware.   EnCase is nowhere close to that.

Of course, nothing beats EnCase for doing actual analysis.
Logged

~~~~~~~~~~~~~~
Ketchup
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.065 seconds with 22 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.