Ethical Hacking Training at InfoSec Institute Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Ghost Norton Fingerprint signature |
|---|---|
| Date: | Sun, 29 May 2005 00:08:52 -0400 |
On Sat, 28 May 2005 19:39:20 PDT, Steve Hailey said:
The oriignal question was along the lines of "how to find the signature," not "would the signature be present in a forensic clone of a drive that already contained the signature." My original information is correct based on the question asked.
Your *original* answer was a bit misleading...
switch.â?? If the original subject media has the Ghost fingerprint present already from previous imaging activity, then yes, this will also be present on the forensic clone.
This is subtly different than what you originally said:
You will typically find the signature for Ghost in the sectors between the Master Boot Record and the first Boot Record. You'll know it when you see it. If the disk was cloned using the proper switches to create a forensically sound sector-by-sector clone, you will not find a signature.
There's *two* clones being discussed here - your forensic clone and an earlier one. If we're discussing the *original* clone being made with those switches, then yes, there won't be a signature on the disk (unless of course the original had aquired a signature from an even *earlier* cloning). If we're discussing the *forensic* clone (an obvious conclusion if you read the sentence as "If you made your forensic clone using the switches you'd want for a forensically sound clone"), there's the implication that doing so would make an existing signature apparently dissapear...
pgpvdCgH9W3NW.pgp
Description: PGP signature
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: Ghost Norton Fingerprint signature, Steve Hailey |
|---|---|
| Next by Date: | Re: Forensic disk duplication modifies the evidence hard disk, Clinton E. Troutman |
| Previous by Thread: | RE: Ghost Norton Fingerprint signature, Steve Hailey |
| Next by Thread: | Forensic disk duplication modifies the evidence hard disk, Steven McLeod |
| Indexes: | [Date] [Thread] [Top] [All Lists] |