Transcript

FileSystemForensics

THINK BIG WE DO

U R Ihttp://www.forensics.cs.uri.edu

Digital Forensics CenterDepartment of Computer Science and Statics

GUID Partition Table

Partitioning

GUID Partition Table

Partitioning

GPT PartitioningGUID Partition Table- Used on Intel IA64 (EFI) Systems- Supports up to 128 Partitions- 64-bit (8 byte) LBA addressing

GUID (Globally Unique Identifier)- Uses 128-bit unique identifiers for- Partition Type- Partition Identifier

Required for Boot Partitions- Microsoft Windows on an EFI System- Mac OS X

GPT PartitioningProtective MBR- Allows compatibility with older systems- Single MBR Partition of type 0xEEPrimary GPT Header- General Layout of the diskPartition Entries- Description of Each PartitionPartition AreaBackup Partition EntriesSecondary GPT Header- Backup Copies- Last Sectors of Disk

Protective MBR

Primary GPT Header

Partition Entries

Partition 1

Partition 2

. . .Other Partitions

. . .

Secondary Partition Entries

Secondary GPT Header

012

34

End of Disk (EOD)EOD-1

EOD-33

GPT PartitioningProtective MBR

Primary GPT Header

Partition Entries

Partition 1

Partition 2

. . .Other Partitions

. . .

Secondary Partition Entries

Secondary GPT Header

012

34

(EOD)EOD-1

EOD-33

Decimal Hex Primary GPT Header0 00 Signature “EFI PART”8 08 Version12 0C GPT Size in Bytes (92)16 10 CRC32 Checksum of GPT Header20 14 Reserved24 18 LBA of Current GPT Structure32 20 LBA of Other GPT Structure40 28 Start LBA of Partition Area48 30 End LBA of Partition Area56 38 Disk GUID72 48 Start LBA of Partition Entries80 50 Number of Entries in Partition Table 84 54 Size of Each Partition Table Entry88 58 CRC32 Checksum of Partition Table92 5C Reserved

Primary GPT Header

GPT PartitioningProtective MBR

Primary GPT Header

Partition Entries

Partition 1

Partition 2

. . .Other Partitions

. . .

Secondary Partition Entries

Secondary GPT Header

012

34

(EOD)EOD-1

EOD-33

Decimal Hex Partition Entry in Partition Table (128 bytes)0 00 Partition Type GUID (128-bits)16 10 Unique Partition GUID (128-bits)32 20 Starting LBA of Partition40 28 Ending LBA of Partition48 30 Partition Attributes56 38 Partition Name in Unicode

Partition Entries

Microsoft Windows limits the number of partition

table entries to 128.

32 sectors = 128 entries ÷ 4 entries per sector

THINK BIG WE DO

U R Ihttp://www.forensics.cs.uri.edu

Digital Forensics CenterDepartment of Computer Science and Statics

GUID Partition Table Partitioning

GUID Partition Table Partitioning

Timothy Henry
00:00
Timothy Henry
00:16
Timothy Henry
02:02
Timothy Henry
04:09
Timothy Henry
07:55
Timothy Henry
10:49
Timothy Henry