Sabtu, 05 September 2015

RECAPRY DATA (PENGEMBALIAN /PENCARIAN DATA YANG TER ENKRIPSI)

DIGITAL FORENSIC
1     IDENTIFICATION
2     PERESERVATION
    - chain of custoday
    - Labeling
    -imaging/Clone(membuat kmbarannya)

3     EXAMINATION (pengujian)
4     ANALYSIS
5     REPORTING/PRODUCK
                                     APLIKASI YG BIASA D GUNAKAN
                                         a.(TESDISK)
                                         b.(AUTOPSY) biasa d buka d brouser.

┌─[budhya@parrot]─[~]
└──╼ $sudo su
[sudo] password for budhya:
┌─[root@parrot]─[/home/budhya]
└──╼ #apt-get install testdisk
Reading package lists... Done
Building dependency tree
Reading state information... Done
The following NEW packages will be installed:
testdisk
0 upgraded, 1 newly installed, 0 to remove and 151 not upgraded.
Need to get 394 kB of archives.
After this operation, 1,419 kB of additional disk space will be used.
Get:1 http://eu.repository.frozenbox.org/mirrors/debian/ jessie/main testdisk i386 6.14-3+b2 [394 kB]
Fetched 394 kB in 3s (104 kB/s)
Selecting previously unselected package testdisk.
(Reading database ... 269039 files and directories currently installed.)
Preparing to unpack .../testdisk_6.14-3+b2_i386.deb ...
Unpacking testdisk (6.14-3+b2) ...
Processing triggers for man-db (2.7.0.2-5) ...
Setting up testdisk (6.14-3+b2) …

 
┌─[root@parrot]─[/home/budhya]
└──╼ #testdisk /dev/sdb
TestDisk 6.14, Data Recovery Utility, July 2013
Christophe GRENIER <grenier@cgsecurity.org>
http://www.cgsecurity.org
┌─[root@parrot]─[/home/budhya]
└──╼ #testdisk /dev/sdb
the disk is name TOSHIBA andthan you (ENTER)
 next you seleck a intel partision and (ENTER)
 Next you seleck ANALYSE And ENTER
 Next you seleck again QUICK SEARCH And ENTER
 Next seleck CONTINUE (ENTER)
 The next you seleck (P) p is is for (list file) for looking your file in direcktory
 the next  is RED FILE in a direck tory this is a file target and copy you mas seleck (C) In a Red file 
 next selec cofy again is finished cofy  is list green copy done
  and search in your pc for paste after copy your file in your list red directory
 and seach from  deroctory pc the last paste after copy and finis

Tidak ada komentar:

Posting Komentar