CD/DVD Imager User's Manual
Total Page:16
File Type:pdf, Size:1020Kb
CD/DVD Imager™ USER’S MANUAL Revised February 20, 2007 Meet WiebeTech’s CD/DVD Imager You’ve earned your warrant and entered the premises intent on capturing data as quickly and efficiently as possible, only to come face to face with a pile of CDs and DVDs which need to be quickly backed up for later analysis. WiebeTech’s CD/DVD Imager comes to your aid. It automatically images and archives CDs and DVDs to hard disk, takes a picture of each CD/DVD and stores it with the disc image. With the WiebeTech CD/DVD Imager, investigations can be performed more quickly, with greater evidence reliability, and with less expense. Just load up the robot and let it fly. The resulting disc images work easily with forensic software such as EnCase, ILook or Forensic Toolkit. Features • Automatically image and archive CDs and DVDs to external or network storage devices • A photograph of the actual disc is taken and stored with the disc image • Disc images are ready for addition to forensic applications such as EnCase, ILook or FTK • MD5 hashes verify that the disc image is not altered during forensic analysis • You can use the included disc imaging tools, or add your own Linux-based disc imaging tool of choice Table of Contents Before Installation 2 Hardware Setup 3 Overview of Forensic Optical Media Captures 5 Hash values 5 Live CD 6 Manual Software Setup 7 Software Setup under Fedora Core 4 7 Linux Primer 8 Operating the CD/DVD Imager 10 Focusing the camera 10 Sample Output 11 Accessing disc images on a Windows computer 12 Advanced Usage 12 FAQs (Frequently Asked Questions) 13 Safety Instructions 14 Glossary 15 Technical Specifications 16 CD/DVD Imager User Manual - 1 - WiebeTech LLC Before Installation 1. Check the accessories with your CD/DVD Imager. Please contact WiebeTech if any items are missing or damaged. The box should contain: CD/DVD Imager 1 WARNING: When removing the Imager Camera mounting arm and camera 1 from the box, DO NOT LIFT OR HOLD IT BY THE DISC ARM. Doing so may USB cable 1 permanently damage the delicate mechanisms that move the arm. Power adapter & wall cord 1 Disc guide pillars 4 Manual and Warranty information (on CD) Save the packing materials for future shipment use. Goods shipped without the original packaging may not be well protected during transport, and will void the product’s warranty. 2. Familiarize yourself with the parts of your CD/DVD Imager. This knowledge will be useful during hardware setup. Front View Rear View 1. Robotic Disc Arm 1. Fan (see warning below) 2. Status Indicator 2. USB Jack 3. Output Bin 3. AC Power Input 4. CD/DVD Drive 4. Power Switch 5. Input Bin WARNING: Do not block the ventilation fan during operation. Overheating may damage the device. CD/DVD Imager User Manual - 2 - WiebeTech LLC Hardware Setup The CD/DVD Imager consists of a CD/DVD-ROM, a mechanical arm (which accesses the tray and input/output hoppers) and a camera arm. The camera arm is mounted over the output tray and provides pictures of each disc as they are captured. 1. Position the camera arm. This is demonstrated in the pictures below: Raise the arm Push the base into the receptacle Secure it in place 2. Install the four guide pillars into the input bin. NOTE: There are two different sets of pillars, with a large or small connector. Place the similar pillars diagonally across from each other. You can use different sizes of media by rotating the four pillars as shown in the images below: CD/DVD Imager User Manual - 3 - WiebeTech LLC 3. Attach the input hopper tray. Use the pictures below as a guide. WARNING: Operating the robot with the input tray improperly attached may result in damage to the robot. Before turning on the power, make sure that you have fully seated the input bin onto the CD/DVD Imager. 4. Attach the USB cables from the robot and camera arm to the forensic workstation. The B-male end connects to the robot. The camera arm already has the USB cable attached. Both A-male ends connect to the computer. USB AC adapter 5. Connect power. Connect the AC adapter to the CD/DVD Imager as shown in the picture above. Connect the wall cord to the AC adapter as shown to the right. Plug the wall cord into a grounded electrical outlet. AC Adapter NOTE: Turning on power to the Imager before booting into Linux may cause Linux not to recognize the Imager. If this happens, Wall Cord simply cycle the Imager’s power. CD/DVD Imager User Manual - 4 - WiebeTech LLC Forensic Optical Media Captures Unlike hard drives, images created from optical discs may vary in minor ways each time the image is taken—even when the same disc and same optical drive are used. This is caused by a variety of factors, such as the presence of dust particles or scratches, and the use of error-catching algorithms that are less robust that those used by hard disk controllers. Considering such factors, any forensic investigation involving evidence on optical media should have the following goals. Goal #1: To acquire disc image files that can be read and analyzed by forensic software tools designed for that purpose. There are a number of such tools available (e.g. FTK, EnCase, etc). Note: these tools are not included with CD/DVD Imager. Goal #2: To be able to prove that the original data on the disc is not altered during copy. This can be assured by the use of imaging software that is forensically trusted for this task. The open-source, Linux-based imaging tools included with CD/DVD Imager are dd and cdrdao. Both of these are widely trusted by the forensic community. However, you may also substitute your own Linux-based imaging tool if you prefer. This may be necessary for some discs—no single imaging tool is likely to handle every disc you encounter. Forensic investigators must often try several tools before successfully imaging unusual or problematic discs. However dd and cdrdao will handle the vast majority of optical discs you are likely to run across. Goal #3: To be able to prove that the disc image file isn't altered after its initial creation. This is done by creating a hash value of the image taken. By running another hash of the disc image after forensically analyzing it, you can prove that the image was not altered during the investigation. Goal #4: To be able to match the disc image with the physical evidence. CD/DVD Imager takes a picture of each disc and stores it with the disc image. A hash value of the picture file is also generated so an analyst can later prove that the picture has not been altered. Hash Values (MD5, SHA-1) When starting the imaging process, you will be able to choose the hash type used. You may select no hashing, hashing with MD5 (selected by default), or hashing with SHA-1. The software will automatically hash both the disc image created as well as the photograph of the disc. MD5 (A 128-bit hash value) is well established and widely trusted, and SHA-1 (160-bit) is becoming more trusted by the forensic community. Because the goal here is not encryption but verification that the disc image is not subsequently altered (without detection), either hash type should be fine. Some forensic departments may have specific rules regarding hash types; thus, both are selectable. NOTE: It is good forensic practice to print a copy of the hash output file after a capture session and keep this (forensically marked) copy in a separate, safe location. In this way the analyst can later prove that there were no alterations to the images after the images were acquired. (If someone gains access to the hash logs, they could alter both the file and the hash log. Thus, a paper copy further strengthens the forensic chain of evidence.) CD/DVD Imager User Manual - 5 - WiebeTech LLC Software Setup Starting with Live CD The simplest way to get started is to use the included Live CD. This CD contains the complete Linux environment required for operation, as well as the software applications you will need. Just put the CD into your computer and reboot. You may need to change the computer’s BIOS settings related to boot order. Make sure your computer’s CD or DVD drive is listed as the first boot device. Wait until after the computer is booted before turning on the CD/DVD Imager. Otherwise, the OS might have difficulty finding the device. 1. Choose Display Mode At the first prompt, you can choose the display mode. The default is text mode. If you press Enter, or wait for 30 seconds, the OS will launch as a text-only environment. Alternatively, you may press F1 and then type the following command to launch in a mode that supports graphics as well as text: linux vga=xxx (“xxx” indicates the resolution type as shown in the list above the prompt. For example, 788 = 800 x 600 x 16 resolution) Using this command will launch the OS in a VGA mode, which will allow you to view the camera feed, adjust the camera’s focus, and view pictures taken by the camera. All other functions of CD/DVD Imager operation can be performed in text-only mode. Note: if the graphics card in your computer is not supported by the video drivers on the Live CD, you will not be able to use a VGA mode.