|
|
|
| Web Hosting |
![]() ![]() |
Basic Forensics: Winhex, Reading sectors on a mounted disk/storage volume |
Mar 24 2008, 09:54 PM
Post
#1
|
|
|
Newbie [ Level 2 ] Group: Members Posts: 13 Joined: 22-March 08 From: Arizona Member No.: 29,306 |
WinHex is a hexadecimal editor that allows you to read sectors on a mounted volume with support for FAT, NTFS, Ext2/3, ReiserFS, Reiser4, UFS, CDFS, UDF file systems. The basic program is available free for download, although there are levels of licenses that can be obtained for to unlock additional features. These include their individual licenses Personal ($56.00), Professional ($105.00), Specialist ($255.00) and X-Ways Forensics ($929.00) which cover the cost for one (1) license of its type.
In the world of IT, a tool like WinHex comes in quite handy when working with data recovery. A supposedly fully formatted floppy disk has no data on it and can be written to. However, when mounted under WinHex, you can access every disk sector and look for key signatures that would suggest fragments of a deleted file still remain on the storage media. Traces of a Microsoft Office document, for example (doc, xls, dot, ppt, xla, ppa, pps, pot, msi, sdw, db, vsd, msg), can be identified by using the File Recovery by Type option under the Tools -> Disk Tools menu to look for headers matching \xD0\xCF\x11\xE0\xA1\xB1\x1A\xE1 in each disk sector. You may also specify your own signatures and label them for quick searching of any file types not listed or supported by this application. Paging through 2880 sectors on a 1.44 MB floppy disk time consuming? No problem, simply clone the disk as a raw image and edit the image on the local file system instead! After being able to recover files that normal PC users would've thought were long gone by now, the significance of using a secure wipe/erase program to properly delete confidential data might be a little more clear. WinHex does support a Wipe Securely File Tool under the Tools menu. With additional license privileges (only available by purchasing an upgraded license), you not only can view the contents of your system's physical memory (RAM) but edit them as well. There are some Specialist features available as well for reconstruction a RAID system or further working with mounted volumes. These features do require a Specialist or fully upgraded license to use without added restrictions. I would highly recommend backing up (or write protecting) any target storage media before experimenting with hex editing disk sectors. Use at your own risk. |
|
|
|
Mar 28 2008, 08:29 PM
Post
#2
|
|
|
Super Member Group: [HOSTED] Posts: 566 Joined: 25-April 05 Member No.: 4,374 myCENTs:33.04 |
It is always fun to see what is on the drive hidden away from the usual means of reading the data. Personally I don’t feel like having someone else reading my hard drive at such a low level so I encrypt the entire hard drive so such things are impossible. My current favorite is TrueCrypt 5.0 (http://www.truecrypt.org/) which now features whole drive encryption. This mean that EVERYTHING except the boot sector on the drive is encrypted. This keeps those nasty “forensics tools” from doing their job. Of course you can see read data but it is a meaningless encrypted blob that doesn’t even have a file system.
|
|
|
|
![]() ![]() |
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:
Similar Topics
| Topic Title | Replies | Topic Starter | Views | Last Action | |||
|---|---|---|---|---|---|---|---|
![]() |
8 | bridenhosen | 1,738 | 5th January 2009 - 01:38 PM Last post by: iG-Ernesto Gramcko |
|||
![]() |
7 | solanky | 3,315 | 19th December 2008 - 09:34 AM Last post by: iG-preety sharma |
|||
![]() |
11 | Propeng | 1,374 | 17th December 2008 - 10:40 PM Last post by: yordan |
|||
![]() |
11 | TheCapo | 448 | 13th December 2008 - 01:07 PM Last post by: tek3D |
|||
![]() |
17 | l337 Nurse Pedestrian | 9,010 | 12th December 2008 - 02:52 AM Last post by: iG-biswarup ghosh |
|||
![]() |
11 | ViRuaL | 2,360 | 10th December 2008 - 10:14 PM Last post by: iG-nick |
|||
![]() |
5 | khalilov | 357 | 1st November 2008 - 06:58 PM Last post by: sparkx |
|||
![]() |
16 | r3d | 4,095 | 8th October 2008 - 03:28 PM Last post by: ml01172 |
|||
![]() |
8 | dhanesh | 1,600 | 10th September 2008 - 02:25 PM Last post by: Guest |
|||
![]() |
1 | chappill | 212 | 8th September 2008 - 01:35 PM Last post by: yordan |
|||
![]() |
6 | RWM2 | 570 | 6th September 2008 - 04:57 AM Last post by: TavoxPeru |
|||
![]() |
5 | bluefish | 1,379 | 11th August 2008 - 06:02 AM Last post by: Gr33nN1nj4 |
|||
![]() |
0 | Ashraful | 445 | 29th July 2008 - 07:02 AM Last post by: Ashraful |
|||
![]() |
15 | proxies | 1,656 | 16th June 2008 - 09:39 PM Last post by: frameworker |
|||
![]() |
1 | kanade | 375 | 30th May 2008 - 08:49 AM Last post by: kanade |
|||
|
Lo-Fi Version | Time is now: 8th January 2009 - 02:49 AM |
© 2009 AstaHost: Free Web Hosting & Technical Discussion, Free Web Hosting. a member of xisto.
Powered by Invision Board. Skin: IPB Forum Skins
Expand / Collapse Navigation



Mar 24 2008, 09:54 PM




