Does anyone recognize the tape drive header?

SDLT 320 Sector 0-
Does anyone recognize this tape header and what was used to create the tape?
Dave MohylaAsked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

David FavorLinux/LXD/WordPress/Hosting SavantCommented:
Hum... Vaguely resembles CPM Disk dump... I could be wrong, since last time I used CPM was... 1982ish...

Looks like a backup of some floppy media of an old school OS... maybe...

One trick you can use is to dump the entire tape using tar, basically telling tar to ingest the entire tape, breaking each EOF marker into a separate file, ending when EOT is hit.

1980s was last time I even saw a mag tape, so this is all from memory.

Best to dump all the tape data to disk, then work on the disk files.

Best, meaning, you'll likely spend a good bit of time pulling your hair out trying to understand data while it's on tape media.

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Dave MohylaAuthor Commented:
Hi David,

I have already performed a dump via Linux, that is what we are looking at.  I can recover files in a forensic format to some extent. The tape was made in 2003. It does not look as if NTbackup made it the MTF begins with TAPE, and it does not have a Veritas header.
David FavorLinux/LXD/WordPress/Hosting SavantCommented:
2003... The format sure looks like some very old OS. The H: looks vaguely Microsoft-ish.

The \\FSERV2 looks like some other OS, without camel case support.

Whew... If the output you provided really is the first tape block + you get no read errors (indicating first block is corrupted), it's unclear.

No search I did turns up any listing of backup tape format which looks like your first block.

Good luck. Looks like decoding this tape may be a long process.
Active Protection takes the fight to cryptojacking

While there were several headline-grabbing ransomware attacks during in 2017, another big threat started appearing at the same time that didn’t get the same coverage – illicit cryptomining.

Dave MohylaAuthor Commented:
Thanks David,
It does look odd!  
Thanks for your input!
Dave MohylaAuthor Commented:
I do believe this was a Microsoft based server and the tape also backed up a network share. I can see standard MS directory hierarchy at text in the images.
Gerald ConnollyCommented:
Can do that dump but in hex it might make more sense
andyalderSaggar maker's framemakerCommented:
caroot = [Computer Associates] Arcserve admin account name.
andyalderSaggar maker's framemakerCommented:
I disagree, CAROOT implies ARCSERVE, no ifs or buts on that score.
David FavorLinux/LXD/WordPress/Hosting SavantCommented:
Marked my answer as best, since it covers generic tape dumping + debugging, which seems to be required to resolve this issue.
andyalderSaggar maker's framemakerCommented:
>Vaguely resembles CPM Disk dump... I could be wrong...

At least you got one bit right ;)
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Storage Software

From novice to tech pro — start learning today.