Archive

Archive for December, 2008

How to Secure the Computer as Evidence?

December 2nd, 2008 Comments off
  • Photograph and log room, position of computer and status of computer;
  • If the computer is “OFF,”  Do Not Turn “ON”;
  • If the computer is “ON,” Do Not Turn “OFF”;
  • Place Evidence tape over each drive slot;
  • Photograph and label back of computer components while they are plugged in;
  • Label all connection ends to allow reassembly if needed;
  • If transporting, treat all components as fragile;
  • Collect all devices such as cables, keyboards and monitors;
  • Collect instruction manuals, documentation, and notes;
  • User notes may contain passwords;

Computer Forensic Example

December 2nd, 2008 Comments off
  • Recovery of over 1000 E-Mails off of a hard drive;
  • A year and half after the individual left the company;
  • After the hard drive had been formatted;
  • After the machine was in use by another user for that year and a half;
  • Best way to remove e-mail from a hard drive is to hit with a sledge hammer and throw it into a furnace;

Computer Forensics Defined

December 2nd, 2008 Comments off

- “Computer Forensics deals with the preservation, identification, extraction and documentation of computer evidence.”*

-  “Computer forensics has also been described as the autopsy of a computer hard disk drive because specialized software tools and techniques are required to analyze the various levels at which computer data is stored after the fact.”*

-  Recovering Information the naked eye can no longer see.

Fundamentals of searching for malfunctions

December 1st, 2008 Comments off

The description above should demonstrate that a HDD is a sophisticated software and hardware device combining electronic and mechanical parts and utilizing the most recent achievements of microelectronics, micromechanics, automatic control theory, magnetic recording theory, and coding theory. HDD repair is impossible without specialized knowledge, special equipment, instruments and tools, and without a specifically equipped location (clean room). However, an expert in computer hardware can perform primary diagnostics of HDD and repair simple failures, perform operations over BAD sectors using software offered by HDD manufacturers.

In the absence of special diagnostic equipment and software HDD diagnostics should begin with connection…

Technologies used for maintaining HDD reliability

December 1st, 2008 Comments off

 With all the complications HDD manufacturers are constantly trying to make user data storage more reliable. To accomplish that they use various methods and technologies in their drives.
 
 Figure 5. Control circuit of spindel of HDD (family WDAC 32500 and WDAC 33100)
 S.M.A.R.T. (abbreviated Self-Monitoring, Analysis, and Reporting Technology) is intended to inform hard drive users about the status of its main parameters. Many motherboard BIOSes support analysis of those parameters at computer power-up and if some critical parameter exceeds its emergency limit an informational message is displayed during computer start-up. Of course, it does…

Computer Forensic Tools(6) – Encase Forensic

December 1st, 2008 Comments off

encase-forensicEnCase Forensic is the industry standard in computer forensic investigation technology. With an intuitive GUI, superior analytics, enhanced email/Internet support and a powerful scripting engine, EnCase provides investigators with a single tool, capable of conducting large-scale and complex investigations from beginning to end. Law enforcement officers, government/corporate investigators and consultants around the world benefit from the power of EnCase Forensic in a way that far exceeds any other forensic solution.

-Acquire data in a forensically sound manner using software with an unparalleled record in courts worldwide.

-Investigate and analyze multiple platforms — Windows, Linux, AIX, OS X, Solaris and more…

HDD malfunctions

December 1st, 2008 Comments off

 ”Nothing is eternal” – that expression applies also to hard disk drives. No matter how reliable a HDD is still it is degraded with time by destructive processes.

 First, a drive is a mechanical and electronic device but all mechanical parts gradually wear out. With time connections between mechanical parts become slack. Numerous ascensions and descents of magnetic heads which occur during each start and stop of magnetic disk rotation destroy the protective layer coating the heads. However, modern manufacturing technology guarantees rather long life for hard drives. Thus, according to the information from the…

Logical structure of disk space

December 1st, 2008 Comments off

Considerable part of disk space in modern drives is hidden from users; it contains service data and an area reserved for substitution instead of defective sectors in a HDD. In normal operation mode it is accessible by drive microcontroller only. Users may access the working area frequently called logical disk space and it is exactly the same capacity as the value indicated in the characteristics of a certain model. Access to the working area represented by a continuous chain of logical sectors is performed in LBA notation from 0 to N. Connection between the logical disk space and physical disk…