(FTK
Imager:
Lesson 1)
{ Install FTK Imager }
Section 0. Background
Information |
- What is FTK Imager?
- The FTK toolkit includes a standalone disk imaging program called
FTK Imager. The FTK Imager has the ability to save an image of a hard
disk in one file or in segments that may be later reconstructed.
- It
calculates MD5 hash values and confirms the integrity of the data before
closing the files.
- In addition to the FTK Imager tool can mount devices
(e.g., drives) and recover deleted files.
-
Lab Notes
- In this lab we will do the following:
- Download FTK Imager.
- Install FTK Imager.
- Legal Disclaimer
- As a condition of your use of this Web
site, you warrant to computersecuritystudent.com that you will not use
this Web site for any purpose that is unlawful or
that is prohibited by these terms, conditions, and notices.
- In accordance with UCC § 2-316, this
product is provided with "no warranties, either express or implied." The
information contained is provided "as-is", with "no guarantee of
merchantability."
- In addition, this is a teaching website
that does not condone malicious behavior of
any kind.
- You are on notice, that continuing
and/or using this lab outside your "own" test environment
is considered malicious and is against the law.
- © 2013 No content replication of any
kind is allowed without express written permission.
Section 1: Log into
Damn Vulnerable WXP-SP2 |
- Start VMware Player
- Instructions
- For Windows 7
- Click Start Button
- Search for "vmware player"
- Click VMware Player
- For Windows XP
- Starts --> Programs --> VMware
Player
- Start Up Damn Vulnerable WXP-SP2.
- Instructions:
- Click on Damn Vulnerable WXP-SP2
- Click on Edit virtual machine Settings
- Note(FYI):
- For those of you not part of my class, this
is a Windows XP machine running SP2.
- Edit Virtual Machine Settings
- Instructions:
- Click on Network Adapter
- Click on the Bridged Radio button
- Click on the OK Button
- Play Virtual Machine
- Instructions:
- Click on Damn Vulnerable WXP-SP2
- Click on Play virtual machine
- Logging into Damn Vulnerable WXP-SP2.
- Instructions:
- Username: administrator
- Password: Use the Class Password or
whatever you set it.
- Open a Command Prompt
- Instructions:
- Start --> All Programs -->
Accessories --> Command Prompt
- Obtain Damn Vulnerable WXP-SP2's IP Address
- Instructions:
- ipconfig
- Note(FYI):
- In my case, Damn Vulnerable WXP-SP2's IP
Address 192.168.1.116.
- This is the IP Address of the Victim
Machine that will be attacked by Metasploit.
- Record your Damn Vulnerable WXP-SP2's
IP Address.
- .
Section 2: Download FTK Imager |
- Open Firefox
- Instructions:
- Start --> All Programs --> Firefox
- Download FTK Imager 3.1.4
- Instructions:
- Place the following URL into the
address textbox (See Picture)
- https://drive.google.com/file/d/0BwWG59jwoT6tMUlSWkNFUlAxanM/view?usp=sharing&resourcekey=0-8LUmLVCgeD3by8eYe8WKcw
- Click Download anyway
- Select the Save File radio
button
- Click on the OK Button
- Note(FYI):
- This lesson is based on FTK Imager
3.1.x. FTK Imager 3.1.x is no longer downloadable from Access
Data.
- In order to complete this lesson, FTK
Imager 3.1.x has been made available on Google Drive. Accordingly,
you must comply with Access Data's
License Agreements.
- The latest version of FTK Imager can be
found below.
- Go To Downloads
- Instructions:
(On Firefox)
- Tools --> Downloads
- Open Containing Folder
- Instructions:
- Right Click on the AccessData_FTK_Imager_3.1.4.zip
- Select Open Containing Folder
- Extract Executable
- Instructions:
- Right Click on AccessData_FTK_Imager_3.1.4.zip
- Select Extract All...
- Extraction Wizard
- Instructions:
- Click Next
- Extraction Wizard (Select a Destination)
- Extraction Wizard (Extraction Complete)
- Instructions:
- Check Show extracted files
- Click Finish
- Open FTK Imager Executable
- Instructions:
- Right Click on the FTK Imager
Executable
- Select Open
- AccessData FTK Imager - InstallShield Wizard
- Instructions:
- Click the Next Button
- AccessData FTK Imager - License Agreement
- Instructions:
- Click the "I accept..." Radio Button.
- Click the Next Button
- AccessData FTK Imager - Destination Folder
- Instructions:
- Click the Next Button
- AccessData FTK Imager - Install
- Instructions:
- Click the Install Button
- AccessData FTK Imager - Complete
- Instructions:
- Un-Check the "Launch AccessData FTK
Imager" checkbox.
- Click the Finish Button
-
Proof of Lab
- Instructions:
- dir "C:\Program Files\AccessData" |
findstr "FTK"
- date /t
- echo "Your Name"
- This should be your actual name.
- e.g., echo "John Gray"
-
Proof of Lab Instructions
- Press both the <Ctrl> and <Alt> keys at
the same time.
- Do a <PrtScn>
- Paste into a word document
- Upload to Moodle
-
|
 
|