Quantcast
Channel: Forensic Focus Forums - Recent Topics
Viewing all articles
Browse latest Browse all 20102

General Discussion: Western Digital SmartWare

$
0
0
I came across one last week. The way I proceeded is as follows 1. I removed the hard drive from the enclosure. 2. Using Image Masster Solo I created a clone (single capture) on another hard drive drive. 3. Using the sata usb adapter from the suspects hard drive enclosure I connected the clone to my forensic machine. If the suspects sata usb adapter is not used the clone will not be recognized. The forensic machine will also not recognise the clone if it a write blocker is used. 4. Once connected to the forensic machine the clone appears as a CD Drive labelled "WD Smartware" 5. Right click and open the Cd Drive which will display a number of folders. 6. Run "Unlock.exe" which will prompt you for the password. 7. It will only give you a number of attempts to put the right password failing which it will ask you if you want to erase the hard drive. 8. I was fortunate that the suspect provided the password when I asked for it. 9. Once the correct password is entered it mounts as a hard disk drive labelled "My Book".. 10. Open the drive and create a logical evidence of the folder "WD_Smartware" In conclusion the sata usb adapter and the password are central to examine the backup files. It appears that the sata usb adapter has some form of software that interacts with the password and then mount the drive containing the backup files.

Viewing all articles
Browse latest Browse all 20102

Trending Articles