{"id":190,"date":"2013-05-05T21:02:33","date_gmt":"2013-05-05T20:02:33","guid":{"rendered":"http:\/\/frosteyes.dk\/?p=190"},"modified":"2013-05-06T06:54:09","modified_gmt":"2013-05-06T05:54:09","slug":"being-the-timothy-mcgee-of-the-family","status":"publish","type":"post","link":"http:\/\/www.frosteyes.dk\/index.php\/linux\/being-the-timothy-mcgee-of-the-family","title":{"rendered":"Being the \u201cTimothy McGee\u201d of the family"},"content":{"rendered":"<p>As a fan of <a title=\"Wikipedia NCIS\" href=\"http:\/\/en.wikipedia.org\/wiki\/NCIS_(TV_series)\" target=\"_blank\">NCIS<\/a>, I have often seen how Timothy McGee and Abby Sciuto is doing their forensic work on computers, where they need to find some information to solve a case. Of cause they are in a crises, and have some magical graphical interfaces telling them all sort of information extremely fast. In the real world things is a bit different.<\/p>\n<p>I decided to write this post, while recovering some mails for my uncle. He had an old computer, which started spontaneous shutdowns because of a thermal event. So he bought a new computer and asked me for help with getting the old mails. At that point I thought it was an easy job, just involving getting the hard drive, put it in my disk cradle, copy the outlook data file to the new computer and import it. When I dismantled the computer, I noticed the hard drive was a bit older then first expected. It had an IDE interface instead of a SATA interface, so my disk cradle idea did not work. No problem, I will just put it in a computer with IDE interface and access the files from this computer. Though luck, when I booted in Windows 7 check disk failed, and asked if I wanted to format the hard drive. Not the question I had hoped for.<\/p>\n<p>The task just got bigger than first imagined. So the first thing would be to prevent any more damage to the data and file system on the disk. So I put the hard drive in my trusty Gentoo Linux machine and did a raw copy of the partition using <a title=\"Wikipedia dd\" href=\"http:\/\/en.wikipedia.org\/wiki\/Dd_(Unix)\" target=\"_blank\">dd<\/a>.<\/p>\n<pre lang=\"bash\">sudo dd if=\/dev\/sdi1 of=\/home\/frosteyes\/charlie\/Bo\/diskImage.img<\/pre>\n<p>Now having the disk image, I can work on getting the mails without risking to destroy anything on the physical disc. I am using testdisk and photorec. They can be installed by <em>emerge testdisk<\/em> on Gentoo Linux.<\/p>\n<p>Using testdisk on the image, it shows that the MFT and MFT mirror are bad. Failed to repair them. This was identical with what chkdsk had reported earlier. So no usable master file table (MFT).<\/p>\n<p>The next task was to run photorec on the disc image as seen below. photorec is a recovery program, which among other file types can detect pst files without having a file sytem on the disk. It resulted in a huge number of folders with files, including a number of pst files.<\/p>\n<figure id=\"attachment_197\" aria-describedby=\"caption-attachment-197\" style=\"width: 398px\" class=\"wp-caption aligncenter\"><a href=\"http:\/\/frosteyes.dk\/wp-content\/uploads\/2013\/05\/photorecRunning.png\"><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-197\" title=\"photorec running\" alt=\"photorecRunning\" src=\"http:\/\/frosteyes.dk\/wp-content\/uploads\/2013\/05\/photorecRunning.png\" width=\"398\" height=\"257\" srcset=\"http:\/\/www.frosteyes.dk\/wp-content\/uploads\/2013\/05\/photorecRunning.png 569w, http:\/\/www.frosteyes.dk\/wp-content\/uploads\/2013\/05\/photorecRunning-300x193.png 300w\" sizes=\"auto, (max-width: 398px) 100vw, 398px\" \/><\/a><figcaption id=\"caption-attachment-197\" class=\"wp-caption-text\">photorec is running on the disc image<\/figcaption><\/figure>\n<p>An then finding the pst files I was looking for.<\/p>\n<pre lang=\"bash\">\r\nfrosteyes@stas ~\/charlie\/Bo $ find .\/ -iname *.pst | xargs ls -l\r\n-rw-r--r-- 1 frosteyes users 81282048  5 maj 17:16 .\/recup_dir.133\/f9541960.pst\r\n-rw-r--r-- 1 frosteyes users   271360  5 maj 17:19 .\/recup_dir.171\/f13814104.pst\r\n-rw-r--r-- 1 frosteyes users 24396800  5 maj 18:46 .\/recup_dir.374\/f47280112.pst\r\n-rw-r--r-- 1 frosteyes users  1033216  5 maj 18:49 .\/recup_dir.414\/f54353688.pst\r\n-rw-r--r-- 1 frosteyes users   271360  5 maj 18:50 .\/recup_dir.416\/f55373800.pst\r\n<\/pre>\n<p>Before handing over the files to my uncle I just tested the files using lspst from libpst. Can be installed with <em>emerge libpst<\/em> on my Gentoo system. It showed that the pst files contains the needed emails.<\/p>\n<p>So all in all it ended up being more forensic work than expected, but quite fun and I felt a bit like McGee from NCIS.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>As a fan of NCIS, I have often seen how Timothy McGee and Abby Sciuto is doing their forensic work on computers, where they need to find some information to solve a case. Of cause they are in a crises, and have some magical graphical interfaces telling them all sort of information extremely fast. In &hellip; <a href=\"http:\/\/www.frosteyes.dk\/index.php\/linux\/being-the-timothy-mcgee-of-the-family\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">Being the \u201cTimothy McGee\u201d of the family<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4,7],"tags":[],"class_list":["post-190","post","type-post","status-publish","format-standard","hentry","category-linux","category-windows"],"_links":{"self":[{"href":"http:\/\/www.frosteyes.dk\/index.php\/wp-json\/wp\/v2\/posts\/190","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.frosteyes.dk\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.frosteyes.dk\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.frosteyes.dk\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/www.frosteyes.dk\/index.php\/wp-json\/wp\/v2\/comments?post=190"}],"version-history":[{"count":32,"href":"http:\/\/www.frosteyes.dk\/index.php\/wp-json\/wp\/v2\/posts\/190\/revisions"}],"predecessor-version":[{"id":221,"href":"http:\/\/www.frosteyes.dk\/index.php\/wp-json\/wp\/v2\/posts\/190\/revisions\/221"}],"wp:attachment":[{"href":"http:\/\/www.frosteyes.dk\/index.php\/wp-json\/wp\/v2\/media?parent=190"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.frosteyes.dk\/index.php\/wp-json\/wp\/v2\/categories?post=190"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.frosteyes.dk\/index.php\/wp-json\/wp\/v2\/tags?post=190"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}