|
Forensics
Linux, dd, and image file Apr 01 2003 04:31PM Sabol, Paul (PSABOL mgmmirage com) (6 replies) Re: Linux, dd, and image file Apr 02 2003 09:02AM Birger Toedtmann (btoedtmann exp-math uni-essen de) |
|
|
Privacy Statement |
<snip>
> Basically, I md5 the original drive, make a working directory on my Linux
> drive, and then 'dd if=/dev/hdc of=testing.bin conv=notrunc,noerror,sync".
> I then make a /mnt/windows directory to be used as the mount point and chmod
> 777 this directory.
All well and fine, but you've just created an image of the entire hard
drive, my friend, which is why mount is complaining, as there clearly
isn't a valid superblock, but instead a master boot record. :)
You should check out the partition table using "fdisk -l /dev/hdc",
then "dd if=/dev/hdc1 ..." if the NTFS partition is the first and/or
the only one on that disk, or use the corresponding partition number.
<snip>
> I do the following:
>
> # losetup /dev/loop0 testing.bin
> # mount -r -t ntfs /dev/loop0 /mnt/windows
Just a note: the following is also possible and saves you one step:
$ mount -t ntfs -o loop ./testing.bin /mnt/windows
Cheers & good luck,
--
Grega Bremec
grega.bremec-at-gbsoft.org
http://najdi.si/
http://www.gbsoft.org/
http://www.noviforum.si/
-----------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com
[ reply ]