todo:removable-flash-media

Removable Flash Media

There is a risk when plugging USB devices or other writeable storage media into a conventional operating system that the OS will write to the device, meaning a clean dump of the original media cannot subsequently be made. To enable as clean as possible a dump to be preserved - even in the case of used devices it is good to avoid making any further changes.

This method uses a forensics-oriented Linux distribution which defaults to blocking all devices in read-only mode to ensure as secure as possible an environment for imaging of writeable storage media.

  1. Dumping via network (preferred, system-level read/write does not need to be turned on)
  1. Dumping to additional device connected to PC (still likely safe but requires system-level read/write ability to be enabled and at least one additional device set to read/write permissions)

[todo: elaborate]

Tools required

Basically the process is the same as Method 2, but you *do not* enable the system-wide write access, instead you just connect your PC to the network and copy your dump to another device.

Tools required

Process

  • Do not connect the external storage media that you wish to dump until instructed to do so.
  • Download CAINE from the link above
  • Either burn the ISO to a DVD or create a bootable live USB using Rufus. Insert the burned disc or USB into your system and reboot into CAINE
  • Check that the system-level mount policy is set to read-only (disk icon in the taskbar should be green). If this is red, right click it and change to read-only.

  • Run UnBlock - this should show you a list of devices that are currently attached to the system.

  • At this stage, connect the media you wish to dump and hit refresh in UnBlock. This should show up in UnBlock now with a device-level policy of writable.

  • Change this to read-only by ticking the checkbox next to it in the listing and then hit OK)
  • From the list of devices, find and make a note of the device name related to the media you wish to dump (for the rest of this guide we'll call this sdX)

  • Open “caine's Home” and, from the list of devices at the left, find either an internal or external hard-drive to which you want to save the image. The device labels should be the same as you can see in your normal OS (e.g. Windows, Storage, Elements etc.) (for the rest of this guide we'll call this $HARDDRIVE)

  • Go back to unblock and find this hard-drive in the list of devices - hopefully it should be obvious from the relative sizes, otherwise you can find device labels by using the command 'lsblk -o name,label' from the command line)

  • Click the checkbox next to the hard-drive and hit OK - this should now show as writable in UnBlock

  • Change the system policy to allow mounting devices in writable mode by right clicking the green disk icon in the task bar and selecting “make writable”

  • Open “caine's Home” again and find your hard-drive at the left - click to mount this. It will mount at /media/caine/$HARDDRIVE.

  • Open the console and dump the USB using the following command 'sudo dd if=/dev/sdX/ of=/media/caine/$HARDDRIVE/backup.img bs=4M status=progress'

  • todo/removable-flash-media.txt
  • Last modified: 2022/01/10 13:36
  • by hiccup