Scan of the Month |
|
Forensic Analysis of A Recovered Diskette Answers |
|
|
1. Who is the probable supplier of drugs to Jimmy Jungle? From the data it appears John Smith is Jimmy Jungle's supplier. Text gathered from the floppy disk includes this name. Other files show maps with street names suggesting the Jones, FLA location. N. Mainstreet could mean that the Main Street address for John Smith is nearby.2. What is the mailing address of Jimmy Jungle's probable drug supplier? The address given in the recovered text file for John Smith is 1212 Main Street, Jones, FL 00001.3. What is the exact location in which Jimmy Jungle received the drugs? Danny's Pier 12 Boat Lunch is diagramed and marked with an X in a green box on both maps recovered. It is located on Shore Line Drive. One map is a BMP file and the other a JPEG file. This may be the place where Jimmy Jungle met with John Smith to pick up the drugs.4. Where is Jimmy Jungle currently hiding? The BMP file is a map where "Hideout 22 Jones" is marked with an X in a green box. The box is near the corner of Jones Ave and Smith Street. This may be where Jimmy Jungle is currently hiding.5. What kind of car is Jimmy Jungle driving? No information about the car Jimmy Jungle is driving was found on the floppy disk analyzed. However the text string, "pw=help" was found possibly indicating that a password protected file may exist.6. Bonus Question: Explain the process that was performed so that there were no entries in the root directory and File Allocation Table (FAT), yet the contents of each file remained in the data area?" It appears Jimmy Jungle formatted the disk to hide the data. A soft or high level format re-initializes the boot sector, and more importantly re-initializes the two file allocation tables and the root directory. A high level format also zeros all information about the individual files -- names, file times e.t.c found in the root directory. However it does not remove the actual data starting at sector 33.
|