Computer Forensics: Hard Disk and Operating Systems

Computer Forensics Computer Forensics: Hard Disk and Operating Systems (Ec-Council Press Series : Computer Forensics) by EC-Council

The Computer Forensic Series by EC-Council provides the knowledge and skills to identify, track, and prosecute the cyber-criminal. The series is comprised of five books covering a broad base of topics in Computer Hacking Forensic Investigation, designed to expose the reader to the process of detecting attacks and collecting evidence in a forensically sound manner with the intent to report crime and prevent future attacks. Learners are introduced to advanced techniques in computer investigation and analysis with interest in generating potential legal evidence. In full, this and the other four books provide preparation to identify evidence in computer related crime and abuse cases as well as track the intrusive hacker’s path through a client system. The series and accompanying labs help prepare the security student or professional to profile an intruder’s footprint and gather all necessary information and evidence to support prosecution in a court of law. Hard Disks, File and Operating Systems provides a basic understanding of file systems, hard disks and digital media devices. Boot processes, Windows and Linux Forensics and application of password crackers are all discussed.

Read More

A case of wrong partition data recovery

Case:Customers use the sudden blue screen normally, so they reinstall the system by themselves, but the operation error and the deprivation system cannot be completed. Solution:The original failure may be a bad drive in the hard disk. On this basis, users have done another destructive operation “error zone””.This operation caused the problem to complexity.Detecting the…

Read More

General Data-Loss Prevention Tips

data-loss The cost of a data loss event is directly related to the value of the data and the length of time that it is needed, but unavailable. Consider:

  • The cost of continuing without the data
  • The cost of recreating the data
  • The cost of notifying users in the event of a compromise

General Data-Loss Prevention Tips

Software and Hardware

  • Document your systems and archive original copies of your software in a safe place.
  • Backup your files on a regular basis, then test and verify that your backup is a complete copy of the original. External drives are an excellent choice for this task.
  • Never upgrade software or hardware without a complete, verified backup available in case you need to restore data.
  • If you are using Microsoft Windows XP, establish System Restore Points before making any significant changes to your system.
  • Write a contingency plan and practice restoring your data in case of problems. Your contingency plan should require, as a minimum:
    • Locating all available backups, including dates and types of backup.
    • Listing and locating all original software packages, detailing updates since the original installation.
    • Locating and making ready an alternate computer.
  • Deploy firewalls and virus protection.
  • Delete unused files and applications. Use a disc defragmenter, which is a program that is usually part of the operating system utilities.

Environment

  1. Ensure proper environmental conditions (stable temperature, humidity and cleanliness) and proper handling to avoid static discharge and accidental dropping.
  2. Physically secure systems from intruders.
  3. Prepare for physical disasters, including use of off-site storage for backup.

The following sections describe types of data recovery and supported formats and manufacturers. RAID data recovery, digital photo recovery, and VMWare workstation data loss are covered in separate articles under “Related Links.”

Laptop Data Recovery

As they are often carried about and exposed to different environmental factors such as heat, water and dust, laptop and notebook computers are far more likely to experience data loss than their office desktop counterparts. Their portability makes these sophisticated and essential in-the-field devices prime candidates for data loss.

Mechanical and electrical failure, software corruption and human error all play a role in data loss. Here are some of the most often noted data loss symptoms and data accessibility problems:

  • Dropped notebook – no longer turns on
  • Inaccessible drives and partitions
  • Applications that are unable to run or load data
  • Corrupted data
  • Virus attacks
  • Hard disk component failure
  • Hard disk crashes
  • Damage due to fire or liquids
  • Media surface contamination and damage
  • Accidental reformatting of partitions
  • Accidental deletion of data

Laptop Disk Drives Supported
You may not know this, but the hard disk drive embedded in your laptop is not necessarily by the same manufacturer as the laptop. Seagate Recovery Services recovers data from all notebook and laptop brands, models and interfaces – that is, from all types of hard disk drives from all manufacturers including Western Digital, Seagate, Toshiba, Fujitsu, Hitachi and Samsung.

Database Recovery

Mission-critical data is often stored in SQL Server, Oracle, Sybase, Exchange Server, Access and other databases that are maintained on networked fileservers. Relational and object-oriented database management technologies are fundamental to modern IT systems, often underpinning the lifeblood applications run by the entire corporation.

Individual media in database servers suffer from the same failure points as disk drives in personal computers and workstations. Experienced system administrators and database administrators know that a relational or object-oriented database environment is fragile unless supported by a comprehensive and well-tested backup plan.

Unfortunately, it is all too common for devices to become corrupt beyond the scope of routine recovery methods:

  • Backup files not recognizable by database engine
  • Database locked as ‘suspect’ preventing access
  • Deleted or dropped tables
  • Accidentally deleted records
  • Corrupted database files and devices
  • Damaged individual data pages
  • Accidentally overwritten database files and devices

Seagate Recovery Services specializes in making inaccessible data accessible again, recovering data from the most complex database configurations.

Database Types Supported

  • Microsoft SQL Server 6.5, 7.0, 2000, 2005, 2008
  • Oracle Lite, 8.x & 9.x, 10x, 11x
  • Sybase SQL Server
  • Sybase SQL Anywhere
  • Interbase
  • MySQL
  • PostgreSQL Standard Databases
  • Microsoft Access

SRS can also make inaccessible data accessible again for all xbase products such as dBase, FoxPro Productivity Applications Microsoft Office (including all versions of Word, Excel and Powerpoint Mail Server and Client Applications), Microsoft Exchange and Outlook Applications, and email systems conforming to the UNIX mbox format, such as Eudora and Netscape.

Server Data Recovery

Fileservers, application servers, mail servers, web servers, NAS devices and custom-built servers form the backbone of corporations’ business records storage systems. Windows servers–the most popular operating systems for servers today–along with Apple OSX, Solaris, HPUX, IAX, and Linux servers, form a significant portion of servers in businesses.

Naturally, the individual media in servers suffer from the same failure points as do drives in personal computers and workstations. However, the increased complexity of many server operating systems results in additional data loss situations:

  • Server registry configuration lost
  • Intermittent drive failure resulting in configuration corruption
  • Multiple drive failure
  • Accidental replacement of media components

Because servers are often utilized for mission-critical operations, customers need to get their data back quickly and securely. SRS services includes options for on-site data recovery, critical 24/7 options, as well as remote data recovery and special options.

Operating Systems and Platforms Supported
SRS technicians are trained on platform-specific configurations, enabling us to recover data from server hardware spanning the most popular brands, such as IBM, Dell, Hewlett-Packard, Sun and others, including:

  • Intel-based platforms for UNIX Operating systems including
    • Solaris, Linux with ext 2,3,4, xfs, reiserfs & jfs filesystems on standalone & RAID volumes in LVM (Logic Volume Management) configuration or without it
    • BSD-based systems such as FreeBSD, OpenBSD and NetBSD, BSDI
    • Apple Mac OSX
    • Legacy OS like QNX, SCO OpenServer, Xenix, UnixWare, LynxOS and so on
  • Intel-based platforms for Non-Unix Operating systems including:
    • Windows NT, 2000, 2003, 2008 servers
  • UNIX and non-UNIX Platforms such as
    • Solaris on Sun/SPARC equipment, with ufs and Veritas VxFS .zfs filesystems
    • HPUX on Hewlett-Packard workstations with hfs and Veritas
    • VxFS file systems on standalone
    • IRIX on SGI workstations with efs and xfs filesystems
    • Legacy VMS & OpenVMS running on Compaq & DEC equipment using ODS file systems
    • AIX on IBM RS/6000 with jfs file systems on LVM volumes

Tape Data Recovery

Server and personal-computer tape backup systems utilizing mm DAT, Travan, Exabyte 8mm, LTO and the various QIC formats are popular and necessary to safeguard your data. However, when these tapes fail, the situation is normally catastrophic, as these tapes were often the only remaining repository of the data. Quite often customers may no longer posses original tape hardware or software to restore from legacy environments.

Fire, smoke, water and even dropping the tape cartridge may damage the media, resulting in data loss. Internal mechanism failure and exposure to extreme temperatures, as well as logical read/write errors on a tape’s file may also result in data loss. Due to the nature of the tape solution, they are designed to withstand time to store archives. Some media if stored incorrectly or stored longer than the life span of the media may degrade causing data loss.

Here are some typical causes of tape failure:

  • Tape drive failure has corrupted tape headers
  • Tape media stretched or snapped
  • Fire & water damage Media surface contamination and damage
  • Accidental reformatting or erasure of tape
  • Accidental overwriting of headers
  • Tape backup software corruption
  • Media degradation due to the age or improper storage
  • Legacy tapes where tape drive or software no longer available

Formats and Manufacturers Supported
Popular backup software–such as EMC, Networker, CA BrightStore (ArcServe) plus the UNIX tar and cpio utilities (and many more)–all use different internal formats. SRS programmers are expertly trained to understand and extract data any type of tape media, regardless of format. SRS recovers data from these tape media formats and manufacturers, among others:

  • DLT III, DLT IV, DLT-1, VS80, VS160 and Super DLT tape
  • LTO 1, 2 , 3, 4, 5
  • 4mm DAT format DDS, DDS-2, DDS-3 and DDS- DAT-72, DAT-160, DAT-320
  • Exabyte 8mm 112m and 160m tapes & Mammoth 1 (Exabyte 8900), Mammoth 2
  • Sony IT and AIT-2, AIT-3 AIT-4, AIT-5 and SAIT
  • Travan TR-1, TR-3, TR-4 and TR-5 tapes
  • QIC tapes
  • QIC Mini-Cartridges
  • Tandberg SLR tapes
  • ADR and ADR2 tapes
  • 9 track 800/1600/6250 bpi
  • Next track
  • IBM 3480/3490/3592 tapes

Tape Backup and File Formats

  • Microsoft Tape Format (MTF) applications such as NT Backup and Symantec (Seagate/Veritas), BackupExec for Window, Backup Exec for NetWare
  • System Independent Data Format (SIDF) applications such as Novell’s Sbackup and Palindrome’s Backup Director
  • IBM Tivoli TSM
  • Computer Associates, Brightstore (Arcserve)
  • Previos/Stac Replica Backup for NT, NetWare
  • EMC (Legato) NetWorker (all platforms)
  • Symantec (Veritas) NetBackup, unix tar, cpio, fbackup, fsdump and ufsdump archives
  • Compaq/DEC VMS Backup
  • Commvault Galaxy/Simpana

For more information, please go to Seagate Recovery Services

Read More

Recommended 1TB Network Attached Storage (NAS)

Network-attached storage (NAS) is data storage or perhaps a data storage device, like a hard disk or RAID array, attached to some type of computer network, supplying data use of different network clients.

NAS systems contain a number of hard drives, frequently arranged into logical, redundant canisters or RAID arrays (redundant arrays of affordable/independent disks). NAS products remove down to file serving using their company servers on the network.

Bestselling 1TB Network Attached Storage (NAS) on Amazon.com:

Seagate BlackArmor NAS 110 1TB Network Attached Storage
(MPN: ST310005MNA10G-RK, Price: $199.99, Amazon.com Price: $149.99)

Seagate BlackArmor NAS 110 1TB Network Attached StorageReview: “A little slower than I hoped. ~40MBps read and ~22MBps write – Sequential. Since the 1Gb ethernet spec can go up to 125MBps theoretical I was hoping it would be in the 80-100MBps range. Encryption requires a USB drive plugged in the front. Just fine if you have a small, old USB flash. The backup software is not the most reliable in recovery, but you get 5 free licenses and for Windows XP it is better than built-in. Use Windows 7’s built-in back up with drive.”

Iomega Home Media 1TB Network Attached Storage
(MPN: 34337, Price: $126.99, Amazon.com Price: $99.99)

Iomega Home Media 1TB Network Attached Storage Review: “very nice case design, internal fan for hard drive, hooks up to router through network at full speed (1000 mps), very fast, although my comp ethernet card is going at 100 mps, fast enough for now untill i get another eternet card, adjustable light brightness through software.”

Buffalo LinkStation Live 1TB Shared Network Attached Storage
(MPN: LS-CH1.0TL, Price: $129.99, Amazon.com Price: $108.90)

Buffalo LinkStation Live 1TB Shared Network Attached StorageReview: “Super easy setup out of the box. Using with Xbox Media Center with the actual original Xbox’s throughout the house. Kids playroom, living room, office. You can setup access rights so kids can only access Kids folder, etc. Also planning to use with Masscool Media Player.”

NAS provides both storage and file systems. This really is frequently compared with SAN (Storage Space Network) products, which offer only block-based storage leaving filesystem concerns about the “client” side. SAN methods include SCSI, Fibre Funnel, iSCSI, ATA over Ethernet, or HyperSCSI.

NAS Manufactors: Zoysia, Cavalry, D-Link, Hammer Storage, Apple, iomega, LaCie, Linksys, Maxtor, Netgear, QNAP, Thecus, Seagate, Western Digital and Synology.

Read More

CD and DVD utilities

CD DVD UtilityMagic Disk
Virtual CD/DVD driver. With this program you can access or mount an ISO image as a virtual CD/DVD drive just like any regular CD/DVD drive. Supports multiple CD/DVD image formats, including: iso, bin, cif, nrg, etc. Freeware for Windows.

Burn4Free
Free DVD and CD burning program for Windows.

BurnCDCC
This freeware utility can be used to burn an ISO file to a CD/DVD disc. Useful e.g. when you have downloaded a Linux OS installation ISO file from the Web.

IsoBuster
CD and DVD data recovery tool. It supports all CD and DVD formats and all common CD and DVD file-systems. Not free.

Read More