본문 바로가기

security/포렌식

Encase 부트 디스크 생성 이미지

포렌식 도구로 유명한 인케이스를 이용하여 부트 디스크를 생성하려고 시도할 때마다 이미지파일 에러가 납니다.가이던스소프트웨어 사이트를 뒤져보니 하단의 링크에서 다운로드가 가능하더군요.

참고하시길 바랍니다..^^



Acquire Zip Drives Through the DOS Version of EnCase®

Acquire Zip Drives Through the DOS Version of EnCase® The following instructions describe creating a boot disk to acquire Zip drives through the DOS version of EnCase®. Be sure you are running the latest versions of EnCase® on your forensic computer.

  1. Download the EnCase® Barebones Boot Floppy Image from HERE and save file to your installation path
  2. Open EnCase® and go to Tools > Create Boot Disk...
  3. With a blank floppy in the drive, leave A selected as Target Diskette and click [Next >]
  4. Select "Overwrite diskette with a boot floppy base image", then click on the ellipsis box below to set the path to your installation path. (By default, bootfloppy.e01 is selected)
  5. For version 3:
    1. At the Copy Files window, click [Add]Browse to your installation directoryHighlight en.exeClick [Open]Click [Finish]
    2. Click [OK] to close the boot disk creation session
    For version 4 and version 5:
    1. At the Copy Files window, right click in the window and select NewBrowse to your installation directoryHighlight en.exeClick [Open]Click [Finish]
    2. Click [OK] to close the boot disk creation session
  6. Create a temporary directory (such as C:\IOMEGA\TEMP)
  7. Download the executable for the Iomega GUEST.EXE file (ftp://download.iomega.com/english/iodrv-dos-x86-10.exe) and save it to the newly created folder
  8. Go to the folder and double-click on IODRV-DOS-X86-10.EXE to extract the files.
  9. Copy all files in that directory (except IODRV-DOS-X86-10.EXE and AUTORUN.EXE) to the floppy (A:).
  10. Shut down the forensic machine (or suspect machine) with the storage drive and Zip drive attached and remove the cables to the hard drives. Start the machine and go into the BIOS, making sure that the BIOS is configured to boot from floppy only
  11. Shut the machine down, connect the cables to the storage drive and Zip drive, and put the boot floppy in the diskette drive.
  12. Boot the machine
  13. At the A:\> prompt, type "GUEST.EXE"
  14. Run EnCase® by typing "EN.EXE", adding the "/B" switch if you get "divide by" errors

출처 : http://www.guidancesoftware.com/support/articles/AcquireZipDrives.asp