1. MARMARA UNIVERSITY
FACULTY OF ENGINEERING
COMPUTER ENGINEERING DEPARTMENT
CSE497 PROJECT
Digital forensics using (Winhex) analysis
Doç. Dr. Melih KIRLIDOĞ
Project Partners:
2. Abdurahman Karataş 150197981
Mohammad Kemal Alturk 150108931
Digital forensics using (Winhex) analysis :
We are using flash disk 4G bytes in our research , firstly we are going to format the USB at all
by dd if=/dev/zero of=/dev/sdb , then format it with fat32 . then it would be an empty flash
disk ready for research.
We are going to use two files as the following :
1
We are looking for two files data using digital forensics analysis :
3. 1) Ali.txt has 256 KB (262.144 bytes)
2) Abdurahman.txt has 64,0 KB (65.536 bytes)
Simple WinHex research
Directory of disk shows 2 files.
1
2
4. The beginning address of ali.txt in data units start from 801000 bytes hexadecimal till
840FF0 bytes which exactly at 16392 sector 16903
3
5. The beginning address of abdurahman.txt in data units start from 841000 bytes hexadecimal
till 850FF0 bytes which exactly at 16904 sector 17031
4
6. The beginning address of metadata at root directory starts from 800000 bytes till 800070
bytes at 16384 sector.
5
The beginning address of fat area for ali.txt starts from CA400 till
CA500 as a chain cluster it starts from 3 66
7. The beginning address of fat area for abdurahman starts from CA500 bytes till
CA540 bytes as a chain cluster it starts from 67 82