Disclaimer of Liability: With respect to this document, neither the Marshall University Forensic Science Center nor any of its employees, makes any warranty, express or implied, including the warranty of fitness for a particular purpose, or assumes any legal liability or responsibility for the accuracy, completeness, or usefulness of any information, apparatus, product, or process disclosed. Any mention of commercial products within the following documents is intended for information purposes only and is not intended to be used as a substitute and/or replacement for an external laboratory s own test validation. It is advised to independently verify any information prior to reliance thereon. Redistribution Policy: MISDE grants permission for the redistribution and use of the following posted document created by MISDE, provided that the following conditions are met. 1) Redistributions of documents, or parts of the documents, must retain the MUFSC/MISDE cover and disclaimer of liability page. 2) Neither the name of the Marshall University Forensic Science Center nor the Information Security and Digital Evidence Laboratory (MISDE) may be used to endorse or promote products derived from the following document. 3) Any reference or quote obtained from the following MISDE document must be properly annotated in the document that the reference is contained therein.
TEST PLAN Test Number: Test Title: FastBlocSE-01 FastBloc Software Edition (SE). Test Date: 4/19/2006 to Purpose and Scope: Guidance Software s FastBloc Software Edition (SE) is a software-based write-blocking and write-protection device that is designed to allow the safe viewing and acquisition of source media for forensic examination purposes. FastBloc SE accommodates writeblock and write-protection for USB, FireWire, SCSI, and IDE enabled devices. FastBloc Software Edition (SE) also possesses the ability to detect and access device configuration overlays (DCO) and host protected areas (HPA) of a source hard disk, making these areas of the hard disk visible to the examiner. This test plan will test the ability of the FastBloc Software Edition (SE) to allow normal hard disk write-block and write-protect operation to occur to source media. This test plan will consist of test scenarios: Requirements: 1) The FastBloc Software Edition (SE) should successfully compute an of a source hard disk attached to the IDE channel/controller of a PC. 2) The FastBloc Software Edition (SE) should allow normal hard disk write-block operation of a source hard disk attached to the IDE channel/controller of a PC. 3) The FastBloc Software Edition (SE) should successfully access any detected DCO and/or HPA that is contained within the source hard disk attached to the IDE channel/controller of a PC. 4) The FastBloc Software Edition (SE) should successfully compute an of a source hard disk attached to attached via USB 2.0 to a PC. 5) The FastBloc Software Edition (SE) should allow normal hard disk write-block and writeprotect operation of a source hard disk attached via USB 2.0 to a PC. 6) The FastBloc Software Edition (SE) should successfully access any detected DCO and/or HPA that is contained within the source hard disk attached via USB 2.0 to a PC. Page 1 of 8
Description of Methodology: An 18.6 GB parallel-ata (PATA) source hard disk will be attached to a PC via the secondary IDE channel/controller. Guidance Software s EnCase Forensic Edition v.5.05a will then be opened and FastBloc Software Edition (SE) will be launched in WRITE BLOCK IDE CHANNEL mode. After recognition of the source disk and write-block status is obtained after a restart of the operating system (Windows XP), an will be the disk using EnCase v.5.05a. Upon successful completion of the hash, the file Test Document.doc will be added to the disk in Windows Explorer. The operating system will then be shutdown and restarted to determine if a write operation was persistent or write-blocked. The PATA disk will then be attached to the PC via USB 2.0 external drive controller. EnCase Forensic Edition v.5.05a will then be opened and FastBloc SE will be launched in WRITE BLOCK USB, FIREWIRE, SCSI DRIVE mode. After recognition of the source disk and writeblock status is obtained, an will be the disk using EnCase v.5.05a. Upon successful completion of the hash, the file Test Document.doc will be added to the disk in Windows Explorer. The unit will then be powered down and write-blocking removed within FastBloc SE; FastBloc SE will then be re-launched and the USB-powered disk will be restarted to determine if a write operation was persistent or write-blocked. A 200 GB serial-ata (SATA) source hard disk (with a 181.4 GB HPA and only 18.6 GB: 39,102,335 sectors of viewable disk space) will be attached to a PC via the secondary IDE channel/controller using the cloning adapter. EnCase Forensic Edition v.5.05a will then be opened and FastBloc Software Edition (SE) will be launched in WRITE BLOCK IDE CHANNEL mode. After recognition of the source disk and write-block status is obtained after a restart of the operating system (Windows XP), an will be the disk using EnCase v.5.05a. Upon successful completion of the hash, the file Test Document.doc will be added to the disk in Windows Explorer. The operating system will then be shutdown and restarted to determine if a write operation was persistent or write-blocked. The SATA disk will then be attached to the PC via USB 2.0 external drive controller and the cloning adapter. EnCase Forensic Edition v.5.05a will then be opened and FastBloc SE will be launched in WRITE BLOCK USB, FIREWIRE, SCSI DRIVE mode. After recognition of the source disk and write-block status is obtained, an will be the disk using EnCase v.5.05a. Upon successful completion of the hash, the file Test Document.doc will be added to the SATA disk in Windows Explorer. The unit will then be powered down and write-blocking removed within FastBloc SE; FastBloc SE will then be re-launched and the USB-powered disk will be restarted to determine if a write operation was persistent or write-blocked Page 2 of 8
Expected Results: 1) The Guidance Software FastBloc SE will successfully allow of an value for the PATA and SATA source hard-disks while attached to the PC via USB 2.0. 2) The Guidance Software FastBloc FE write-block device will successfully prevent hard disk modification to the PATA and SATA source hard disks while attached to the PC via USB 2.0. 3) An the PATA and SATA source hard disks attached via USB 2.0 after the write attempt will match the original of the disk. 4) The Guidance Software FastBloc SE will successfully allow of an value for the PATA and SATA source hard-disks while attached to the PC via the IDE channel/controller. 5) The Guidance Software FastBloc FE write-block device will successfully prevent hard disk modification to the PATA and SATA source hard disks while attached to the PC via the IDE channel/controller. 6) An the PATA and SATA source hard disks attached via IDE channel/controller after the write attempt will match the original of the disk. Test Scenarios: Test Number Environment: Actions: Assigned Reqt s 01-01 Source PATA Disk 01-02 Source PATA Disk Folder added to ; FastBloc SE restarted 01-03 Source PATA Disk Expected Results: PATA hard disk 01-04 N/A Compare hash 01-05 Source PATA Disk Page 3 of 8
01-06 Source PATA Disk Folder added to ; FastBloc SE restarted 01-07 Source PATA Disk 01-08 N/A Compare hash 01-09 Source SATA Disk 01-10 Source SATA Disk 01-11 Source SATA Disk Folder added to ; FastBloc SE restarted 01-12 N/A Compare hash 01-13 Source SATA Disk 01-14 Source SATA Disk 01-15 Source SATA Disk Folder added to ; FastBloc SE restarted PATA hard disk SATA hard disk SATA hard disk Page 4 of 8
01-16 N/A Compare hash Test Data Description: Test Data Set: Parallel-ATA (PATA) Hard Disk Drive: Seagate Barracuda ATA III Model: ST320414A Serial Number: 7eC0AS9Y Part Number: 9R3004-301 Firmware Number: 3.05 20 Gigabyte Ultra ATA HDD Drive Parameters: Cylinders: 16383 Heads: 16 Sectors: 63 Addressable Sectors: 39,102,336 Installed Software: Windows XP 32 Bit O/S w/ SP2 Microsoft Office 2003 Pro Dell GX270 Drivers and Utilities Disk Serial-ATA (SATA) Hard Disk Drive: Maxtor Diamondmax 10 Model: SATA/150 Serial Number: B41AV2BH 200 Gigabyte SATA-150 HDD 18.6 GB Viewable Disk Space 181.4 GB Host Protected Area (unallocated/hidden) LBA: 398297088 Page 5 of 8
SUMMARY REPORT Test Number: Test Title: FastBlocSE-01 FastBloc Software Edition (SE). Test Date: 2/15/2006 to 2/17/2006 Test Description: This test documents the ability of the FastBloc Software Edition (SE) to successfully prevent write-attempts to parallel-ata and serial-ata hard disk drives. This test will document the ability of FastBloc SE software write-blocker to produce consistent algorithm s. Additionally, the test will document the software s ability to detect the presence and successfully access an HPA or DCO contained within the disk. Forensic Tool: Title: Manufacturer: Model Number: Serial Number: FastBloc Software Edition (SE) Guidance Software N/A N/A Test Results: Test Number Environment: Actions: Assigned Reqt s 01-01 Source PATA Disk 01-02 Source PATA Disk Folder added to ; FastBloc SE restarted 01-03 Source PATA Disk 01-04 N/A Compare hash 01-05 Source PATA Disk Expected Results: PATA hard disk Results: Page 6 of 8
01-06 Source PATA Disk Folder added to ; FastBloc SE restarted 01-07 Source PATA Disk 01-08 N/A Compare hash 01-09 Source SATA Disk 01-10 Source SATA Disk 01-11 Source SATA Disk Folder added to ; FastBloc SE restarted 01-12 N/A Compare hash 01-13 Source SATA Disk 01-14 Source SATA Disk 01-15 Source SATA Disk Folder added to ; FastBloc SE restarted PATA hard disk SATA hard disk SATA hard disk Page 7 of 8
01-16 N/A Compare hash Requirements: 1) The FastBloc Software Edition (SE) should successfully compute an of a source hard disk attached to the IDE channel/controller of a PC. 2) The FastBloc Software Edition (SE) should allow normal hard disk write-block operation of a source hard disk attached to the IDE channel/controller of a PC. 3) The FastBloc Software Edition (SE) should successfully access any detected DCO and/or HPA that is contained within the source hard disk attached to the IDE channel/controller of a PC. 4) The FastBloc Software Edition (SE) should successfully compute an of a source hard disk attached to attached via USB 2.0 to a PC. 5) The FastBloc Software Edition (SE) should allow normal hard disk write-block and writeprotect operation of a source hard disk attached via USB 2.0 to a PC. 6) The FastBloc Software Edition (SE) should successfully access any detected DCO and/or HPA that is contained within the source hard disk attached via USB 2.0 to a PC. Observations: N/A Limitations: N/A Recommendations: N/A Page 8 of 8