Security Basics mailing list archives

Re: Hard Drive Forensics Question


From: "Razi Shaban" <razishaban () gmail com>
Date: Mon, 6 Oct 2008 02:03:31 +0400

On Mon, Oct 6, 2008 at 1:23 AM, Murda Mcloud <murdamcloud () bigpond com> wrote:
So you mean similar to writing 0 s to the drive?
Like dd if=/dev/zero of=/dev/hdax ?
or from dev/random?

Yes.

Just wasn't sure why you said 'copy and paste and delete'-it didn't make
sense to me.

I assumed minimal knowledge, I figured that copying, pasting,
deleting, and repeating would be the method that anyone could
understand.

Also, what would be the point of deleting the data after you have randomly
generated it? Surely if you have overwritten everything then deleting it
seems superfluous.

Delete it so as to be able to write over it again. Multiple
write-overs ensure that no data may be recovered.

And why do you feel that random is better?

If it is actual files that are copied, they may be recovered.
Depending on the nature of those files, opinions could be made either
way. If it's random data, nothing can be retrieved and they are left
with nothing to work with. If they are accusing him of wrong-doing
that he is innocent of, he should leave them with as little as
possible to work with, in my opinion.


Regards,
Razi Shaban


Current thread: