Solved

linux paths helix boot CD

Posted on 2014-12-31
4
389 Views
Last Modified: 2015-02-05
I am using a free boot CD called Helix 3, which comes with a dos type utility to take a forensics image (replica copy) of an internal HDD (not encrypted). I have booted my system into helix, and selected the appropriate utility (linen)... applications > forensics and IR > linen

The linen app lists all physical and logic HDD in the machine.  

For example the internal HDD is listed as (/dev/sda/):

/dev/sda1
/dev/sda2
/dev/sda3

And the USB drive on which I want to write a copy of the internal HDD to (/dev/sdb1:

/dev/sdb1

I then chose the acquire option, which prompts for which drive I want to take a copy of. So I chose the "sda" option which will include all logical drives. It then (this is where the issue is) prompts for a path and file name on which to write the image to. When I put a path of /dev/sdb/sdb1 or /dev/sdb1/ it doesnt like it, and fails. Is there a standard naming convention for linux drives when specifying a path to write a file to? By default its just trying to write the drive to the sba1 drive (which maybe because it is the first partition on the list of drives on the machine)

Completely lost and there is very little in the way of user guides for this utility...
0
Comment
Question by:pma111
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
4 Comments
 
LVL 3

Author Comment

by:pma111
ID: 40525230
It looks like issue could be that you first need to use terminal to cd to the external drive, and also mount as read/write, any idea how to dismount and then mount as read/write? or at least verify how it is currently mounted
0
 
LVL 3

Author Comment

by:pma111
ID: 40525306
if anyone fancies trying this the link to the boot CD is http://www.e-fense.com/products.php and its the link within:

•If you are looking for the free, original Helix (2009R1) you need Helix3

I am trying to write a copy out using an NTFS formatted HDD
0
 
LVL 63

Accepted Solution

by:
btan earned 500 total points
ID: 40525337
you may want to check out this forum on Helix and ext USB as ref
To mount the NTFS volume as RW in Helix....From root shell or sudo:
mount -t ntfs-3g /dev/hdx /media/hdx -o force

force is for forcing a mount when the volume was umounted improperly which that will be the case when using mkntfs to format it.
http://www.forensicfocus.com/Forums/viewtopic/t=2180/

and also this pdf on the step through on mounting (quite similar as above) using autopsy
https://dercyber.files.wordpress.com/2013/09/digital-forensic-analysis-using-helix-and-autopsy-forensic-imaging.pdf
0
 
LVL 3

Author Comment

by:pma111
ID: 40525365
That command appears to have done the trick!

Thanks!
0

Featured Post

What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Every server (virtual or physical) needs a console: and the console can be provided through hardware directly connected, software for remote connections, local connections, through a KVM, etc. This document explains the different types of consol…
Google Drive is extremely cheap offsite storage, and it's even possible to get extra storage for free for two years.  You can use the free account 15GB, and if you have an Android device..when you install Google Drive for the first time it will give…
Learn several ways to interact with files and get file information from the bash shell. ls lists the contents of a directory: Using the -a flag displays hidden files: Using the -l flag formats the output in a long list: The file command gives us mor…
Learn how to navigate the file tree with the shell. Use pwd to print the current working directory: Use ls to list a directory's contents: Use cd to change to a new directory: Use wildcards instead of typing out long directory names: Use ../ to move…

733 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question