Documenti di Didattica
Documenti di Professioni
Documenti di Cultura
----------------------------------------------------------------------------
/gif-3-0: This directroy contained one file that was a match to sm1.gif. The has
h of the matched file is listed below
d25fb845e6a41395adaed8bd14db7bf2 00000000.gif
/jpg-4-0: This directory contain a match to haxor2.jpg. The hash of the matched
file is listed below.
84e1dceac2eb127fef5bfdcb0eae324b 00000001.jpg
This directory also contained a match to paul.jpg. The hash of the matched file
is listed below.
37a49f97ed279832cd4f7bd002c826a2 00000002.jpg
/pdf-25-0: This directory contains a match to the file lin_1.2.pdf. The hash of
the matched file is listed below.
e026ec863410725ba1f5765a1874800d 00000018.pdf
/pdf-26-0: This directory contains a match to the orginal file, nlin_14.pdf. The
hash of the matched file is listed below.
5b3e806e8c9c06a475cd45bf821af709 00000020.pdf
Please note that the MD5 hashes are listed first and then the recovered file nam
e is listed.
-----------------------------------------------------LIST OF FILES THAT COULD NO
T BE RECOVERED------------------------------------------------------------------
------
I was unable to recover the missing "2003_document.doc" file. I belive this mayb
e because the signiture that scalpel uses for word documents does not match the
signiture of this document.
I was also unable to recover the file "enterprise.wav". This maybe due to the fa
ct that scalpel's .wav signiture does not match this .wav file. Even though scal
pel
found a .wav file, it did not match "enterprise.wav".
"holly.xls" was another file that i was unable to recover. This is because scalp
el does not have a .xls signiture.
Both the "pumpkin.jpg" and "shark.jpg" were also unrecoverable. I suspect this i
s because scalpels signitures did not match these spefic .jpg's.
"sm1.gif" was another file that I was unable to carve. This is because the signi
ture generated by this file does not match the one that scalpel has.
Although scalpel did carve what it thought to be a total of three .mov files, no
ne of them matched the orginal surf.mov.
Scalpel does not have a signiture to match .wmv files. As a result both "surf.wm
v" and "domopers.wmv" we not recovered.
Scalpel does not have a signiture to match .ppt files. As a result "test.ppt" wa
s not recovered.
Scalpel did not match any .zip files, even though it has a .zip signiture. I sus
pect that the signiture generated by "wword60t.zip" is not a match to the .zip
signiture that is included in scalpel.
All of the above files may have been recovered if I used a different tool like F
oremost. Scalpel is known to have issues with missing files while data carving a
s
explained by Antonio Merola in his paper, Data Carving Concepts.
/pgp-32-0: This directory did not contain any matches to any orginal files. I su
spect this is due to the signiture matching generating false positives.
/rpm-34-0: This directory did not contain any matches to any orginal files. I su
spect this is due to the signiture matching generating false positives.
/tif-8-0: This directory did not contain any matches to any orginal files. I sus
pect this is due to the signiture matching generating false positives.
/wav-35-0: This directory did not contain any matches to any of the orginal file
s. I suspect this is due to the signiture matching generating false positives.
/wpc-23-0: This directory did not contain any mathces to any of the orginal file
s. I suspect this is due to the signiture matching generating false positives.
/mov-10-0: This directory did not contain any matches to any of the orginal file
s. I suspect this is due to the signiture matching generating false positives.
/mov-11-0: This directory did not contian any matches to any of the orginal file
s. I suspect this is due to the signiture matching generating false positives.
Please see the "Audit.txt" output below for the excact file names. The excat fil
e names are not listed here for reasons of effiency.
---------------------------------------------------------WHY IS DATA CARVING HAR
D-------------------------------------------------------------------------------
-------
Carving files is difficult because often files can be fragmented, which means th
ere data chunks are out of order, or in some cases the data chunks may be missin
g or
corrupt.
Carving files can also be difficult because there are chances for false postives
and false negatives. A signiture may match a file that it is not supposed to a.
k.a
false positive. Or a signiture may fail to match a file a.k.a flase negative.