(FTK
Imager Lite:
Lesson 2)
{ Create FTK Imager Lite
ISO with WinISO }
Section 0. Background
Information |
- What is the Purpose of this lab?
- In this lab I am showing a student how to
create an ISO from FTK Imager Lite.
- Running FTK Imager from a CD or ISO does
not require a forensics investigator to actually install software on the
machine that is being analyzed.
- What is FTK Imager Lite?
- The Forensic Toolkit Imager (FTK Imager) is
a commercial forensic imaging software package distributed by AccessData.
- The FTK Imager Lite version can be
installed and executed from a CD/DVD or USB media.
- What is WinISO?
- WinISO is a professional CD/DVD/Blu-ray
image file utility tool that can: Make disc image files from CD/DVD/Blu-ray
Drive. Convert image files between ISO / BIN and other formats.
(Including NRG, CCD and MDS image file formats) Extract, edit, rename
ISO files directly.
- Pre-Requisite Labs
-
WinISO: Lesson 1: Install WinISO
-
Lab Notes
- In this lab we will do the following:
- Create a VMware Shared Folder
- Download FTK IMAGER LITE
- Burn FTK IMAGER LITE to an ISO/CD
- Test FTK IMAGER LITE ISO/CD
- Legal Disclaimer
- As a condition of your use of this Web
site, you warrant to computersecuritystudent.com that you will not use
this Web site for any purpose that is unlawful or
that is prohibited by these terms, conditions, and notices.
- In accordance with UCC § 2-316, this
product is provided with "no warranties, either express or implied." The
information contained is provided "as-is", with "no guarantee of
merchantability."
- In addition, this is a teaching website
that does not condone malicious behavior of
any kind.
- Your are on notice, that continuing
and/or using this lab outside your "own" test environment
is considered malicious and is against the law.
- © 2015 No content replication of any
kind is allowed without express written permission.
Section 1: Log into
Damn Vulnerable WXP-SP2 |
- Start VMware Player
- Instructions
- For Windows 7
- Click Start Button
- Search for "vmware player"
- Click VMware Player
- For Windows XP
- Starts --> Programs --> VMware
Player
- Start Up Damn Vulnerable WXP-SP2.
- Instructions:
- Click on Damn Vulnerable WXP-SP2
- Click on Edit virtual machine Settings
- Note(FYI):
- For those of you not part of my class, this
is a Windows XP machine running SP2.
- Edit Virtual Machine Settings
- Instructions:
- Click on Network Adapter
- Click on the Bridged Radio button
- Click on the OK Button
- Play Virtual Machine
- Instructions:
- Click on Damn Vulnerable WXP-SP2
- Click on Play virtual machine
- Logging into Damn Vulnerable WXP-SP2.
- Instructions:
- Click on Administrator
- Password: Supply Password
- Press <Enter> or Click the Arrow
Section 2: Enabled
VMware Shared Folder |
- Virtual Machine Settings...
- Instructions:
- Player --> Manage --> Virtual Machine
Settings...
- Folder Sharing
- Instructions:
- Click the Options Tab
- Click on Shared Folder
- Click on the Enabled until power off or
suspend radio button
- Click on the Add button
- Add Shared Folder Wizard
- Instructions:
- Click on the Next Button
- Browse to Shared Folder
- Instructions:
- Click the Browse... button
- Browse For Folder
- Instructions:
- Select either your C: Drive or USB:
Drive
- Note:
In my case, I am using a USB Drive (G:)
- Click on Make New Folder
- Name Folder
- Instructions:
- Name the folder --> "FTK
IMAGER LITE ISO"
- Click the OK Button
- Name the Shared Folder
- Instructions:
- Host path:
G:\FTK
IMAGER LITE ISO
- Note:
In my case, I am using a USB Drive (G:)
- Name: FTK IMAGER LITE ISO
- Click Next
- Specify Shared Folder Attributes
- Instructions:
- Check the Enable this share checkbox
- Click the Finish button
- View Shared Folder Results
- Instructions:
- Notice the share that you just created
- Click the OK Button
Section 3: Verify
Network Connectivity |
- Open a Command Prompt
- Instructions:
- Start --> All Programs --> Accessories
--> Command Prompt
- Obtain Damn Vulnerable WXP-SP2's IP Address
- Instructions:
- ipconfig
- Note(FYI):
- In my case, Damn Vulnerable WXP-SP2's IP
Address 192.168.1.116.
- Record your Damn Vulnerable WXP-SP2's
IP Address.
Section 4: Download
FTK IMAGER LITE |
- Open Firefox
- Instructions:
- Start --> All Programs --> Firefox
- Navigate to FTK Imager Lite
- Instructions:
- Place the following URL into the
address textbox and press enter (See Picture)
- http://www.accessdata.com/support/product-downloads
- Click on FTK IMAGER Arrow
- Click the FTK Imager Lite version 3.1.1
Download Link
- Save FTK IMAGER LITE
- Instructions:
- Click the Download Now button
- Click the Save File radio button
- Click the OK button
- Save Location
- Instructions:
- Navigate to Desktop --> My Documents
--> Downloads
- Click the Save Button
- Go To the Downloads Folder
- Instructions:
- Tools --> Downloads
- Open Containing Folder
- Instructions:
- Right Click on Imager_Lite_3.1.1.zip
- Click Open Containing Folder
- Extract Files
- Instructions:
- Right Click on Imager_Lite_3.1.1.zip
- Click on Extract All...
- Extraction Wizard
- Instructions:
- Click the Next Button
- Select a Destination
- Instructions:
- Click the Next Button
- Extract Completion
- Instructions:
- Click the Finish Button
Section 5: Create
FTK IMAGER LITE ISO |
- Start DoISO
- Notes(FYI):
- It is not necessary to use WinISO to
burn FTK Imager Lite to an ISO. You can use Nero, Roxio, or
whatever. However, WinISO is free and good.
- Instructions:
- Click the Start Button
- All Programs --> WinISO -->
WinISO
- Add Directory
- Instructions:
- Click on Actions
- Click on Add Directory...
- Source Location
- Instructions:
- Navigate to the following location
- C:\Documents and
Settings\Administrator\My Documents\Downloads\Imager_Lite_3.1.1
- Click the OK Button
- Set CD-label name
- Instructions:
- Click on Actions
- Click on Set CD-label name
- Rename Label
- Instructions:
- Rename CD Label to FTK
- Save ISO (Part 1)
- Instructions:
- Click File
- Click Save as...
- Save ISO (Part 2)
- Instructions:
- Navigate to Desktop --> My Documents
--> Downloads
- File name: IMAGER_LITE_3.1.1.ISO
- Save as type: Standard ISO9660
Format(*.ISO)
- Click the Save Button
Section 6: Copy ISO
to VMware Shared Folder |
- Create VMware Shared Folders Desktop Shortcut
- Instructions:
- Navigate to
\\vmware-host
- Right Click on Shared Folders
- Select Create Shortcut
- Click the Yes Button
- Copy ISO
- Instructions:
- Navigate to the following directory
- C:\Documents and
Settings\Administrator\My Documents
- Right click on Imager_Lite_3.1.1.iso
- Select Copy
- Navigate to the VMware Shared Folders
- Instructions:
- Double Click on the VMware Shared
Folders located on the desktop
- Paste ISO File
- Instructions:
- Navigate to the FTK IMAGER LITE ISO
-
\\vmware-host\Shared
Folders\FTK IMAGER LITE ISO
- Right Click in the white window pain
(See Picture)
- Select Paste
Section 7: Test the
ISO/CD Image |
- Virtual Machine Settings...
- Instructions:
- Click Player
- Navigate to Manage --> Virtual Machine
Settings...
- Set CD/DVD
- Instructions:
- Highlight CD/DVD (IDE)
- Check the Connected Checkbox
- Click the Use ISO image file radio
button
- Click the Browse... button and navigate
to the ISO location.
- In my case, G:\FTK IMAGER LITE
ISO\IMAGER_LITE_3.1.1.ISO
- Click the OK Button
- Start FTK Imager from CD
- Note(FYI):
-
A Windows Explorer window should have
opened up to the D: drive.
- Instructions:
- Navigate to D:\Imager_List_3.1.1
- Right Click on FTK Imager.exe
- Select Open
- Congratuations
- Note(FYI):
- Congratuations you successfully burned
FTK IMAGER LITE to a CD and tested it!!!
-
Proof of Lab
- Instructions:
- dir D:\ | findstr "FTK"
- date /t
- echo "Your Name"
- This should be your actual name.
- e.g., echo "John Gray"
-
Proof of Lab
Instructions
- Press the <Ctrl> and <Alt> key at the
same time.
- Press the <PrtScn> key.
- Paste into a word document
- Upload to Moodle
-
|
 
|