Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 31 guests online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Forensics
Good HDD Forensics tool on BT5
EH-Net
May 24, 2013, 06:11:42 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Forensics
(Moderator:
don
) >
Good HDD Forensics tool on BT5
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: Good HDD Forensics tool on BT5 (Read 4968 times)
0 Members and 1 Guest are viewing this topic.
Deadpool614
Newbie
Offline
Posts: 27
He who dares, wins
Good HDD Forensics tool on BT5
«
on:
April 02, 2012, 05:37:57 AM »
So I've recently started looking into digital forensics and was wondering which tool on BT5 that EH would recommend for data recovery for HDD. I currently have a 750Gb laptop HDD that recently crapped out and I wondered if it was possible to recover data from it?
Logged
CIO/G-6 C|EH ....Taking the first steps down a long path.
jimbob
Guest
Re: Good HDD Forensics tool on BT5
«
Reply #1 on:
April 02, 2012, 05:53:43 AM »
Hi,
If the disk is failing but still working i.e. you can read the raw data from the disk then you could image the disk with a tool like ddrescue and try to recover the data. If the disk does not power up, is not recognised or you cannot transfer data from it then you're most likely out of luck.
You can check out this article on BT5 forensics for some ideas and examples.
http://technology-flow.com/articles/backtrack-5-complete-tut/forensics/
Regards,
Jimbob
Logged
millwalll
Guest
Re: Good HDD Forensics tool on BT5
«
Reply #2 on:
April 02, 2012, 06:28:25 AM »
Yah it really does depends on the state of the HDD if its failing to boot it could just have a bad sector on it that pretty easy to repair. Most of the good tools I came across you need to pay for sadly.
Logged
Deadpool614
Newbie
Offline
Posts: 27
He who dares, wins
Re: Good HDD Forensics tool on BT5
«
Reply #3 on:
April 02, 2012, 09:29:56 AM »
Jimbob:
I'll have to give that article a look over. I purchased the Laptop about 8 months ago and the HDD crapped out about month 7 :/ I did some basic troubleshooting and what I could gather from the HP website was that the HDD failed (not so helpful). I have recently come into poession of the cables needed and a forensic bridge to hook it to my other laptop to try to rip the data.
Jamie:
Yeah, I had found a few tools but they were all kinda $$$ I know at some point I'll break down and purchase one eventually but I'd rahter do it once I have a better grasp of what's out there. At this point the laptop won't even go to the BIOS screen. I feel the HDD attempt to spin up but then it just stops. It sucks because I had a good amount of music and documents on there :/
Logged
CIO/G-6 C|EH ....Taking the first steps down a long path.
3xban
Hero Member
Offline
Posts: 608
Re: Good HDD Forensics tool on BT5
«
Reply #4 on:
April 02, 2012, 10:56:19 AM »
If the laptop doesn't get to BIOS then there are other issues most likely, easy test on whether the rest of the hardware is good is to use a bootable CD/DVD/USB image. This will ensure the MoBo and other hardware are functioning. Bad drive will not prevent the BIOS from posting. But a bad MoBo, RAM or CPU will. Bad RAM or CPU will usually cause error beeps unless the CPU is really fried.
For the drive I typically keep an IDE/SATA to USB adapter handy. This lets you connect the drive as if it was an external one. If it is accessible then like Jamie said, you probably just have some data corruption. If it is not accessible and you don't hear it spinning up, then you might have a mechanical failue and there isn't much you can do with your limited budget. If you store the drive in the freezer (in a zip lock freezer bag) for a couple hours, that sometimes helps getting it to spin up enough to get data off it.
Good luck!
Logged
Certs: GCWN
(@)Dewser
sil
Hero Member
Offline
Posts: 549
Re: Good HDD Forensics tool on BT5
«
Reply #5 on:
April 02, 2012, 11:37:03 AM »
Just download FTK imager (
http://accessdata.com/support/adownloads
) and go from there. Not necessarily a fan of forensics tools on a pentesting OS. FTK Imager's sole purpose is data recovery.
Logged
http://www.infiltrated.net/mgz/puppylecter.jpg
Deadpool614
Newbie
Offline
Posts: 27
He who dares, wins
Re: Good HDD Forensics tool on BT5
«
Reply #6 on:
April 02, 2012, 11:54:28 AM »
Well after doing some more looking into it I'm pretty sure the mobo is fried. I swapped RAM with a buddy's laptop and still nothing. I also tried my USB copy of BT4 with no luck
Quote
Just download FTK imager (
http://accessdata.com/support/adownloads
) and go from there. Not necessarily a fan of forensics tools on a pentesting OS. FTK Imager's sole purpose is data recovery.
Thanks, I'll have to look into this one when I have some free time later.
Logged
CIO/G-6 C|EH ....Taking the first steps down a long path.
Joshsevo
Sr. Member
Offline
Posts: 278
Re: Good HDD Forensics tool on BT5
«
Reply #7 on:
July 01, 2012, 04:20:37 PM »
You may be out of luck all together and the HDD is just bad and nothing can read it or even see it. I had this 2 wks ago with a case I am working on.
It was a USB external drive. I tried it with Encase, FTK, a Knoppix boot CD, a Tableau TD1 and even a Tableau USB Bridge. Nothing worked. The computer wouldn't even see it so we had to write a NO Findings report on it.
Logged
Security+, Network+, C|EH, CHFI, CPT
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
News Items and General Discussion About EH-Net
: ÌÀÃÀÇÈÍ ÌÎÄÍÎÉ ÎÄÅÆÄÛ APPLE-FASHION!
(0) by
Infabeemace
News Items and General Discussion About EH-Net
: When your benjamin will be to your own car and truck clean up
(0) by
areluctes
Network Pen Testing
: Want a challenge? Want a GXPN practice exam?
(0) by
ajohnson
GCIH - GIAC Certified Incident Handler
: Passed my GCIH
(8) by
ajohnson
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(29) by
ajohnson
GCIH - GIAC Certified Incident Handler
: GCIH Free Practice test attempt
(1) by
prats84
Greetings
: Hi from the UK
(4) by
MrTuxracer
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.