EXT3FS Keyword Search #1

Digital Forensics Tool Testing Image (#4)

http://dftt.sourceforge.net

Introduction

This test image is an EXT3FS file system with several ASCII strings. There are only 4 strings to search for, so this one is quite simple and short. It only tests the basic features of EXT3FS.

Download

This test image is a 'raw' partition image (i.e. 'dd') of an EXT3FS file system. The file system is 5MB and is compressed to 4MB. The MD5 of the image is 30e7f792cc853e34e17335b243605d3a. This image is released under the GPL, so anyone can use it.

Search Terms

These should all be performed case sensitive and not as regular expressions. Results Form

NumStringSector - OffsetFragment - OffsetFileNote
1first330 - 100165 - 100/, /., /.., /lost+found/..File Name
 first392 - 100196 - 100inode #8Journal entry
 first432 - 100216 - 100inode #8Journal entry
 first2416 - 1811208 - 181/file1Allocated file
2second2419 - 5091209 - 1021/file2Fragmented String
3third2420 - 801210 - 80/file3 (deleted)Unallocated file
4slacker2417 - 1791208 - 691/file1Slack space of file1

Author

Brian Carrier (carrier <at> digital-evidence <dot> org) created the test cases and the test image. This test was released on November 24, 2003.

Disclaimers

Neither Purdue University or CERIAS sponsor this work.

These tests are not a complete test suite. These were the first ones that I thought of and no formal theory was put into their design.

Passing these tests provides no guarantees about a tool. Always use additional test cases (and email them to me so we can all benefit!).

SourceForge Logo


Brian Carrier [carrier <at> digital-evidence <dot> org] Last Updated: Nov 23, 2003