Documenti di Didattica
Documenti di Professioni
Documenti di Cultura
! Mac OS X
! Darwin core
! composed of code developed by Apple and code derived from the
BSD UNIX variant
! compatible with the Single UNIX Specification
! Extended Format File System (HFS+)
OS X System Artifacts
! Introduced with Mac OS 8.1
! Supports much larger disks than HFS
COMP 2555: Principles of Computer Forensics ! File Manager utility
Autumn 2014
http://www.cs.du.edu/2555 ! Reading, writing, and storing data to physical media
! Finder
! A volume is any storage medium used to store files ! First 1024 bytes and last 512 bytes of volume are not
! Can be all or part of a hard disk used
! A file consists of at least two parts: ! HFS+ has five special files that store the file system
! Data fork structures required to access folders, files and attributes
! Contains data that the user creates ! Extents of these files are described in the Volume Header
! Resource fork
Stores application information or supporting data for a file
!
! $AllocationFile
! E.g. icons, context menus, etc.
! Bitmap that tracks which allocation blocks are in use
! Similar to alternate data streams in NTFS
! Is like any other file, so can be non-contiguous
! Allocation block corresponding to a fork are tracked as
extents ! $StartupFile
! A set of contiguous allocation blocks (or clumps) ! Holds information to help boot systems that do not have
knowledge of HFS+ file storage structures (B+-trees)
! Like Linux, OS X places all volumes under the root ! Beneath the root directory are
directory “/” ! Users: parent directory for user home directories
! Beneath the root directory are ! Volumes: parent directory for mounted volumes
! Applications: standard location for all installed OS X ! Similar to /mnt or /media in Linux
applications ! bin and sbin: contains command-line utilities
! Library: supporting data that may be needed to be modified ! private: contains OS X versions of /tmp, /var and /etc
during program execution
! E.g. preferences and recent items
! Network: items in the Network domain
! System: operating system specific files
! Like System32 in Windows
! Network configuration ! Swap files and hibernation data are stored under
! Stored in various plist files under /Library/Preferences/ /private/var/vm
SystemConfiguration ! Swap files contains sections of memory
! preferences.plist has the hostname of the computer ! May persist on disk for some time
! com.apple.network.identification.plist has a running list of ! Hibernation files are “sleep images”
previously assigned network addresses with time stamps ! Any technique used for processing unstructured data are
! com.apple.Bluetooth.plist contains list of Bluetooth devices applicable to these files
ever paired with the system
14 OS X User Artifacts
15 OS X User Artifacts
18 References