Football Fans: Download the 2012 Schedule App from Google Play!


Go Back   Android Forums > Android Community > The Lounge > Computers & IT



Reply
 
LinkBack Thread Tools
Old September 1st, 2011, 10:52 PM   #1 (permalink)
Frank Burns Eats Worms!
 
9to5cynic's Avatar
 
Join Date: Feb 2011
Location: Evo Root Forum, Lounge, Forum Games.
Posts: 3,280
 
Device(s): Evo 4G - CleanRom 2.0 (April '12)
Thanks: 1,761
Thanked 1,122 Times in 785 Posts
Send a message via AIM to 9to5cynic
Default File Carving

Hey all, I figured this is the most 'right' place for this topic, if I'm wrong please move it to the proper place.

Okay, I'm in a forensics class, and we are starting file carving. For those not in the know, we are using a hex editor to find the header and footer of specific file types within an image of a floppy disk.

My problem comes with the first task, we have to manually find the headers and footers by comparing several files of different types.

Does anyone have tips for this? I am going through five or so files (dll for example) and they all have so many in common. Going through this is taking some time, and I gotta finish this before I can look into the dump of the floppy.


The instructor said that headers and footers are usually the first and last 2-20 bytes, but I'm getting matches well past that. So I really don't know if say, the header should be ending after 6 bytes, or 26.


Any tips or help would be greatly appreciated.

9to5cynic is offline  
Reply With Quote
Sponsors
Old September 2nd, 2011, 09:27 AM   #2 (permalink)
Member
 
Join Date: May 2011
Location: Near Stirling, Scotland
Posts: 138
 
Device(s): HTC Desire HD on Cyanogen CM7 (for now)
Thanks: 10
Thanked 29 Times in 20 Posts
Default

do u have to use a particular hex editor?

only reason i ask is that useing hexprobe for example

http://www.hexprobe.com/hexprobe/hex_editor.htm

will show the heade rin the header field for you lol
Haggistech is offline  
Reply With Quote
Old September 2nd, 2011, 08:59 PM   #3 (permalink)
Frank Burns Eats Worms!
 
9to5cynic's Avatar
 
Join Date: Feb 2011
Location: Evo Root Forum, Lounge, Forum Games.
Posts: 3,280
 
Device(s): Evo 4G - CleanRom 2.0 (April '12)
Thanks: 1,761
Thanked 1,122 Times in 785 Posts
Send a message via AIM to 9to5cynic
Default

Yeah, we can use whatever program we want, but what I am really looking for is a method of finding these headers and footers manually (might be on a test or something).

I am looking into various linux hex editors right now, tried ghex, but it doesn't have a select range as far as I see, something that would be incredibly helpful for file carving. Anyone have ideas?

(EDIT: Started using hexedit, it's a command line hex editor. Very nice. It has all the features I'm looking for as far as carving goes...)
Still wondering about any tips for finding the headers and footers.
9to5cynic is offline  
Last edited by 9to5cynic; September 2nd, 2011 at 09:48 PM. Reason: Returning to Federation Space.
Reply With Quote
Old September 2nd, 2011, 10:29 PM   #4 (permalink)
Antidisestablishmentarian
 
johnlgalt's Avatar
 
Join Date: Oct 2009
Location: 3rd Rock
Posts: 8,431
 
Device(s): Motorola® DROID® BIONIC®
Thanks: 1,836
Thanked 1,610 Times in 1,154 Posts
Send a message via ICQ to johnlgalt Send a message via MSN to johnlgalt Send a message via Yahoo to johnlgalt Send a message via Skype™ to johnlgalt johnlgalt@gmail.com
Default

This oughta start helping out the process. For a few well established image types, see Using Image File Headers To Verify Image Format

In general, Wotsit is a great resource for me, but I've never actually checked to see if it contains actual file structure info, such as headers - give it a shot - Wotsit.org
__________________

Files for the Motorola® DROID® BIONIC®:
Motorola USB drivers v5.5.0- 32bit | Motorola USB drivers v5.5.0- 64bit | Motorola RSD Lite v5.7
johnlgalt is online now  
Reply With Quote
Old September 3rd, 2011, 08:54 PM   #5 (permalink)
Frank Burns Eats Worms!
 
9to5cynic's Avatar
 
Join Date: Feb 2011
Location: Evo Root Forum, Lounge, Forum Games.
Posts: 3,280
 
Device(s): Evo 4G - CleanRom 2.0 (April '12)
Thanks: 1,761
Thanked 1,122 Times in 785 Posts
Send a message via AIM to 9to5cynic
Default

Thanks, checking out those links. I'll just have to wait and see what the instructor says about these file footers. I know I could just google them, and be done with it, but I'd really like to actually do the assignment. (lame)
9to5cynic is offline  
Reply With Quote
Old September 3rd, 2011, 10:50 PM   #6 (permalink)
Antidisestablishmentarian
 
johnlgalt's Avatar
 
Join Date: Oct 2009
Location: 3rd Rock
Posts: 8,431
 
Device(s): Motorola® DROID® BIONIC®
Thanks: 1,836
Thanked 1,610 Times in 1,154 Posts
Send a message via ICQ to johnlgalt Send a message via MSN to johnlgalt Send a message via Yahoo to johnlgalt Send a message via Skype™ to johnlgalt johnlgalt@gmail.com
Default

Here's my take - I Google for information that will help me to better understand the problem - not information that is the answer.

It works much better in the long run - you look up the needed info and then do your work.

If you don't know, for example, that a certain file always has the footer
Quote:
%------#%%$@bbg
(imaginary example) then how the hell are you going to look for it? So, it's not a justification, it's a matter of fact and a matter of life. People are going online all the time to get info to make better informed decisions - credit reports, health related facts, entertainment choices, shopping advice, etc. - why should this be any different?
johnlgalt is online now  
Reply With Quote
The Following User Says Thank You to johnlgalt For This Useful Post:
9to5cynic (September 3rd, 2011)
Old September 3rd, 2011, 11:08 PM   #7 (permalink)
Frank Burns Eats Worms!
 
9to5cynic's Avatar
 
Join Date: Feb 2011
Location: Evo Root Forum, Lounge, Forum Games.
Posts: 3,280
 
Device(s): Evo 4G - CleanRom 2.0 (April '12)
Thanks: 1,761
Thanked 1,122 Times in 785 Posts
Send a message via AIM to 9to5cynic
Default

Well, we are getting an excel sheet with all the info on it eventually, but the instructor wants us to open several files in a hex editor and analyze them manually. Headers is easier, but I swear I have forty bytes match for the footer, no idea where it starts.

I agree, google for help, not the answer is the way to go.
9to5cynic is offline  
Reply With Quote
Old September 4th, 2011, 06:09 PM   #8 (permalink)
Antidisestablishmentarian
 
johnlgalt's Avatar
 
Join Date: Oct 2009
Location: 3rd Rock
Posts: 8,431
 
Device(s): Motorola® DROID® BIONIC®
Thanks: 1,836
Thanked 1,610 Times in 1,154 Posts
Send a message via ICQ to johnlgalt Send a message via MSN to johnlgalt Send a message via Yahoo to johnlgalt Send a message via Skype™ to johnlgalt johnlgalt@gmail.com
Default

Ahhh. I see now, you're almost in a pre-test situation, i which you have to see if you can figure out the headers and footers locations / beginning points on your own before receiving the info in the spreadsheet....

Were the types of files specified for you, or are you flying blind?
johnlgalt is online now  
Reply With Quote
Old September 4th, 2011, 09:00 PM   #9 (permalink)
Frank Burns Eats Worms!
 
9to5cynic's Avatar
 
Join Date: Feb 2011
Location: Evo Root Forum, Lounge, Forum Games.
Posts: 3,280
 
Device(s): Evo 4G - CleanRom 2.0 (April '12)
Thanks: 1,761
Thanked 1,122 Times in 785 Posts
Send a message via AIM to 9to5cynic
Default

Nahh.. we have the excel sheet (which was half finished by the instructor) with about 20 files and the homework which has 15 total files, some are repeats though.

I just did the WMV file, and I got 3026b2758e66cf11a6d900aa0062ce6c, but I looked it up online and the website I checked said it stops at 3026b275 or so....

I have no idea know to know where to the header stops and the rest of the file begins. I guess I'll figure that out next class lol.
9to5cynic is offline  
Reply With Quote
Old September 4th, 2011, 11:38 PM   #10 (permalink)
Antidisestablishmentarian
 
johnlgalt's Avatar
 
Join Date: Oct 2009
Location: 3rd Rock
Posts: 8,431
 
Device(s): Motorola® DROID® BIONIC®
Thanks: 1,836
Thanked 1,610 Times in 1,154 Posts
Send a message via ICQ to johnlgalt Send a message via MSN to johnlgalt Send a message via Yahoo to johnlgalt Send a message via Skype™ to johnlgalt johnlgalt@gmail.com
Default

If you looked at 5 different WMV files then you'd have a basis to compare - the common parts would be the header and the place (position) where it changes would be the beginning of the next part...

Same for every other file....




johnlgalt is online now  
Reply With Quote
Sponsors
Old September 5th, 2011, 12:03 AM   #11 (permalink)
Frank Burns Eats Worms!
 
9to5cynic's Avatar
 
Join Date: Feb 2011
Location: Evo Root Forum, Lounge, Forum Games.
Posts: 3,280
 
Device(s): Evo 4G - CleanRom 2.0 (April '12)
Thanks: 1,761
Thanked 1,122 Times in 785 Posts
Send a message via AIM to 9to5cynic
Default

Yeah, I had five or so files loaded up....

Perhaps I need a more 'random' selection for files. Picking files from the same source might be causing this added... headache? lol.
9to5cynic is offline  
Reply With Quote
Old September 5th, 2011, 12:05 AM   #12 (permalink)
Antidisestablishmentarian
 
johnlgalt's Avatar
 
Join Date: Oct 2009
Location: 3rd Rock
Posts: 8,431
 
Device(s): Motorola® DROID® BIONIC®
Thanks: 1,836
Thanked 1,610 Times in 1,154 Posts
Send a message via ICQ to johnlgalt Send a message via MSN to johnlgalt Send a message via Yahoo to johnlgalt Send a message via Skype™ to johnlgalt johnlgalt@gmail.com
Default

I was just about to suggest that as well. A good way to do it would be to make your own files as well for reference....
johnlgalt is online now  
Reply With Quote
Old September 5th, 2011, 12:09 AM   #13 (permalink)
Antidisestablishmentarian
 
johnlgalt's Avatar
 
Join Date: Oct 2009
Location: 3rd Rock
Posts: 8,431
 
Device(s): Motorola® DROID® BIONIC®
Thanks: 1,836
Thanked 1,610 Times in 1,154 Posts
Send a message via ICQ to johnlgalt Send a message via MSN to johnlgalt Send a message via Yahoo to johnlgalt Send a message via Skype™ to johnlgalt johnlgalt@gmail.com
Default

Hey, another piece of advice - If you ever need to perform forensic analysis on an active registry hive, I highly recommend DCSoft's Registry Extender (RegeditX). Right now it is in Beta, so it is free, and he's also incorporated the old Registry Crawler into it - hands down the fastest registry search tool....

RegEditX - Tweaks for the Windows Registry Editor (REGEDIT)
johnlgalt is online now  
Reply With Quote
Old September 5th, 2011, 12:15 AM   #14 (permalink)
Frank Burns Eats Worms!
 
9to5cynic's Avatar
 
Join Date: Feb 2011
Location: Evo Root Forum, Lounge, Forum Games.
Posts: 3,280
 
Device(s): Evo 4G - CleanRom 2.0 (April '12)
Thanks: 1,761
Thanked 1,122 Times in 785 Posts
Send a message via AIM to 9to5cynic
Default

Cool, I'll look into that. I'm always down for 'free' things




9to5cynic is offline  
Reply With Quote
Old September 5th, 2011, 12:13 PM   #15 (permalink)
Antidisestablishmentarian
 
johnlgalt's Avatar
 
Join Date: Oct 2009
Location: 3rd Rock
Posts: 8,431
 
Device(s): Motorola® DROID® BIONIC®
Thanks: 1,836
Thanked 1,610 Times in 1,154 Posts
Send a message via ICQ to johnlgalt Send a message via MSN to johnlgalt Send a message via Yahoo to johnlgalt Send a message via Skype™ to johnlgalt johnlgalt@gmail.com
Default

Considering I have a 100 GB / month Newsgroup sub, nah, not suspicious at all.
johnlgalt is online now  
Reply With Quote
Old September 6th, 2011, 12:48 AM   #16 (permalink)
Over Macho Grande?
 
alostpacket's Avatar
 
Join Date: Nov 2009
Location: NY
Posts: 7,090
 
Device(s): GalaxyNexus(LTE), NexusOne, OG Droid, GalaxyTab 10.1(LTE), Eris, Logitech Revue (fishtank)
Thanks: 4,164
Thanked 3,126 Times in 1,292 Posts
Default

Use a knife with a serrated edge and simmer in olive oil for ten minutes prior to carving, then just a dash of thyme and serve. Goes best with white wine rather than red.
alostpacket is offline  
Reply With Quote
Reply

Bookmarks


Go Back   Android Forums > Android Community > The Lounge > Computers & IT User CP
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT -5. The time now is 03:19 PM.
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.
Custom vBulletin Skins by: Relivo