Security Basics mailing list archives
Re: Copying HDDs for forensic purposes?
From: Byron Sonne <blsonne () rogers com>
Date: Mon, 17 Nov 2003 16:21:50 -0500
Best practice I've used is to boot off a knoppix CD with a second hard drive in the machine, mounted as /mnt. Then from a command prompt `dd if=/dev/hda1 of=/mnt/drive.img` Do this for each partition you want to image After you have the copy, you can remove the original drive, and mount the img file by using loopback, `mount /mnt/drive.img /mnt2 -o loop ro` Ibelieve is the syntax for a read-only loopback. Substitute paths as needed.
Nice thing is that works across multiple operating systems as well... rather handy just to be able to run 'strings' against windows disks.
-- For good, return good. For evil, return justice. --------------------------------------------------------------------------- Forum Systems PRESIDIO: PGP / XML GATEWAY APPLIANCEThe Presidio integrates PGP data encryption and XML Web Services security to simplify the management and deployment of PGP and reduce overall PGP costs by up to 80%. FREE WHITEPAPER & 30 Day Trial - http://www.securityfocus.com/sponsor/ForumSystems_security-basics_031027 ----------------------------------------------------------------------------
Current thread:
- Copying HDDs for forensic purposes? Spencer D'oro (Nov 17)
- Re: Copying HDDs for forensic purposes? Kelly Martin (Nov 17)
- Re: Copying HDDs for forensic purposes? Felecia Vlahos (Nov 17)
- RE: Copying HDDs for forensic purposes? Sgt. Elias (Nov 18)
- RE: Copying HDDs for forensic purposes? Sgt. Elias (Nov 19)
- <Possible follow-ups>
- RE: Copying HDDs for forensic purposes? Hunt, Jim (Nov 17)
- RE: Copying HDDs for forensic purposes? Steven A. Fletcher (Nov 17)
- SV: Copying HDDs for forensic purposes? Thomas Westlund (Nov 17)
- RE: Copying HDDs for forensic purposes? jay . stapleton (Nov 17)
- Re: Copying HDDs for forensic purposes? Byron Sonne (Nov 17)
- RE: Copying HDDs for forensic purposes? Gene LeDuc (Nov 17)
- RE: Copying HDDs for forensic purposes? Amin Lalji (Nov 18)
- RE: Copying HDDs for forensic purposes? Bermingham, Bob (Nov 18)
- RE: Copying HDDs for forensic purposes? Suramya (Nov 18)
- RE: Copying HDDs for forensic purposes? Steven Vallarian (Nov 18)