- evan@edlap:/media/4A169A33169A204D/Forensic/live$ ls chroot/
- dev proc sys
- evan@edlap:/media/4A169A33169A204D/Forensic/live$ ls target/
- evan@edlap:/media/4A169A33169A204D/Forensic/live$ sudo fdisk -l ../WD80GBIMAGES/WD6GBEXTRACTED.raw
- Schijf ../WD80GBIMAGES/WD6GBEXTRACTED.raw: 6448 MB, 6448619520 bytes
- 255 koppen, 63 sectoren/spoor, 784 cilinders, totaal 12594960 sectoren
- Eenheid = sectoren van 1 * 512 = 512 bytes
- Sectorgrootte (logischl/fysiek): 512 bytes / 512 bytes
- in-/uitvoergrootte (minimaal/optimaal): 512 bytes / 512 bytes
- Schijf-ID: 0xbd4bbd4b
- Apparaat Opstart Begin Einde Blokken ID Systeem
- ../WD80GBIMAGES/WD6GBEXTRACTED.raw1 * 63 11936294 5968116 83 Linux
- ../WD80GBIMAGES/WD6GBEXTRACTED.raw2 11936295 12594959 329332+ 5 uitgebreid
- ../WD80GBIMAGES/WD6GBEXTRACTED.raw5 11936358 12594959 329301 82 Linux wisselgeheugen
- evan@edlap:/media/4A169A33169A204D/Forensic/live$ sudo cp ../WD80GBIMAGES/WD6GBEXTRACTED.raw WD6GBEXTRACTED.raw
- evan@edlap:/media/4A169A33169A204D/Forensic/live$ md5sum WD6GBEXTRACTED.raw
- ce8b2f91e056df306268f1e9ccfdaa4c WD6GBEXTRACTED.raw
- evan@edlap:/media/4A169A33169A204D/Forensic/live$ ls
- chroot target WD6GBEXTRACTED.raw
- evan@edlap:/media/4A169A33169A204D/Forensic/live$ sudo kpartx -v -a WD6GBEXTRACTED.raw
- [sudo] password for evan:
- add map loop0p1 (252:1): 0 11936232 linear /dev/loop0 63
- add map loop0p2 (252:2): 0 658665 linear /dev/loop0 11936295
- add map loop0p5 : 0 658602 linear 252:2 63
- evan@edlap:/media/4A169A33169A204D/Forensic/live$ sudo mount /dev/mapper/loop0p1 target
- evan@edlap:/media/4A169A33169A204D/Forensic/live$ ls target/
- bin boot cdrom dev etc home initrd initrd.img lib media mnt opt proc root sbin srv sys tmp usr var vmlinuz
- evan@edlap:/media/4A169A33169A204D/Forensic/live$ sudo mount -o bind target/proc chroot/proc
- evan@edlap:/media/4A169A33169A204D/Forensic/live$ sudo mount -o bind target/dev chroot/dev
- evan@edlap:/media/4A169A33169A204D/Forensic/live$ sudo mount -o bind target/dev/pts chroot/dev/pts
- evan@edlap:/media/4A169A33169A204D/Forensic/live$ sudo mount -o bind target/sys chroot/sys
- evan@edlap:/media/4A169A33169A204D/Forensic/live$ sudo chroot chroot/ /bin/bash
- chroot: failed to run command `/bin/bash': No such file or directory
- evan@edlap:/media/4A169A33169A204D/Forensic/live$
- -----------------------------
- evan@edlap:/media/4A169A33169A204D/Forensic/live$ sudo mount -o bind /proc target/proc
- evan@edlap:/media/4A169A33169A204D/Forensic/live$ sudo mount -o bind /dev target/dev
- evan@edlap:/media/4A169A33169A204D/Forensic/live$ sudo mount -o bind /sys target/sys
- evan@edlap:/media/4A169A33169A204D/Forensic/live$ sudo chroot target/ /bin/bash
- root@edlap:/# su stickieman
- stickieman@edlap:/$ ls
- bin boot cdrom dev etc home initrd initrd.img lib media mnt opt proc root sbin srv sys tmp usr var vmlinuz
- evan@edlap:/media/4A169A33169A204D/Forensic/live$ fuser -m dev/
- evan@edlap:/media/4A169A33169A204D/Forensic/live$
SHARE
TWEET
Untitled
a guest
Nov 10th, 2012
3
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
RAW Paste Data
