Create an account Home  ·  Topics  ·  Downloads  ·  Your Account  ·  Submit News  ·  Top 10  
Modules
· Home
· Content
· FAQ
· Forensic Downloads
· Forensics Feedback
· Forums
· Recommend Us
· Statistics
· Surveys
· Top 10
· Topics
· Training Reviews
· Web Links
· Your Account

Our Membership

Latest: vacckev
New Today: 3
New Yesterday: 1
Overall: 26163

Computer Forensics
This is a free and open peer to peer medium for digital and computer forensics professionals and students. Please help us maintain it by contributing and perhaps linking to us from your own website.

Recent Posts

 computer forensics or information security
 LinkedIn Forensic Toolset - Beta Testers
 duplicators which can image without removing hard drive
 SMART for Linux - copy mount point
 Stegnography

Computer Forensics World Forums


Pages Served
We received
28694788
page views since August 2004

Security Sources

Firewalls
Cryptography
ISO 17799 ISO 27001
ISO 17799 Toolkit
ISO 27001 & 27000
Disk Analysis
Security Policies

Computer Forensics World: Forums

Computer Forensics World :: View topic - Need Help Basic Forensic Questions
 Forum FAQForum FAQ   SearchSearch   UsergroupsUsergroups   ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 

Need Help Basic Forensic Questions

 
Post new topic   Reply to topic    Computer Forensics World Forum Index -> General Computer Forensic Issues
View previous topic :: View next topic  
Author Message
ForensicNewbie12
Newbie
Newbie


Joined: Jun 15, 2012
Posts: 1

PostPosted: Sat Jun 16, 2012 3:50 am    Post subject: Need Help Basic Forensic Questions Reply with quote

I need help with some basic questions. Looking on the web I have gotten conflicting information. Thanks in advance for your help. A lot of questions from this newbie:

- Is Metadata definitively or generally lost when you completely delete a file?

- When I run Recuva I get MAC dates but they are all the same?

- Are filenames and paths lost when you completely delete a file?

- How are clusters allocated - first fit? Does this put all clusters in the beginning of disk thus allowing unallocated clusters to be overwritten?

- How do you find out when a file was deleted?

- There is no reliable Metadata from carved files. Correct?

Thanks again.
Code:
Back to top
View user's profile
binarybod
Newbie
Newbie


Joined: Feb 22, 2010
Posts: 64
Location: Nottingham UK

PostPosted: Tue Jul 03, 2012 6:34 pm    Post subject: Reply with quote

The answer to most of these questions is completely file system specific and even then probably depends on the manner and in which the file was deleted and the application used to do so.

I would give different answers to these questions depending if the file system was HFS(+), Ext(2, 3 or 4), btrfs, FAT or NTFS to name but a few.

As for Recuva, I've never used it because there are better open source alternatives. I know what they are doing because I can read the code.

Paul
Back to top
View user's profile
ChrisParker
Newbie
Newbie


Joined: Jan 23, 2006
Posts: 10

PostPosted: Fri Aug 10, 2012 12:15 am    Post subject: Reply with quote

Hi,

Please consider reading File System Forensics by Brian carrier. It'll answer a lot, if not most of your questions. When a file is deleted, metadata generally speaking is still present. Several factors come into play (level of system/user activity, number of new files introduced, size of the volume, cleaning tools used, etc).

Metadata can also persist in Link files (as an example). So even if the file is wiped, metadata structures are lost (MFT/dir files), you could still recover timestamps.

Also consider metadata within the file (in case you are carving).
Back to top
View user's profile
Display posts from previous:   
Post new topic   Reply to topic    Computer Forensics World Forum Index -> General Computer Forensic Issues All times are GMT + 10 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum

Powered by phpBB 2.0.10 © 2001 phpBB Group
phpBB port v2.1 based on Tom Nitzschner's phpbb2.0.6 upgraded to phpBB 2.0.4 standalone was developed and tested by:
ArtificialIntel, ChatServ, mikem,
sixonetonoffun and Paul Laudanski (aka Zhen-Xjell).

Version 2.1 by Nuke Cops © 2003 http://www.nukecops.com

Forums ©

 

TMs property of their respective owner. Comments property of posters. © 2007 Computer Forensics Science World.
Digital forensic computing news syndication: Computer Forensics Training News or UM Text
Software is copyrighted phpnuke.org (c)2003, and is free under licence agreement. All Rights Are Reserved.