You are on page 1of 9

Dina Hamada

22057136

Digital Forensics

Dr.Hani Qusa

HW1
-Create folder named "Digital Forensics" on the desktop.
-Create file and call it "password.txt" on the "Digital Forensics" folder.

-Edit the file and write some data


-Open txt file in Hex editor as shown .

-take the hash value of the file and save it before deleting the file ,to
compere with the new hash value after recovery

-shift+delete the file (password)


-view the last activity from the program

try to recover the deleted file by the program EaseUS data recovery
-save the recoverd file on disktop for example.

-open this recoverd file on Hex editor and compere it with the old file .

take the hash value of recovered file and then compere it with the old
value
Secound
In this experiment ..we build file in flash
memory then shift delete the file ..

After full the memory with videos and images (big data that can over
write on the real location of deleted file ) ,we try to recover the deleted
file .

Actually , we can't retrieve the deleted file because the resent big files
has written above the deleted data (title and data of the file has lost!)
Hint// in the second experiment i don’t work it because I couldn’t full
my flash memory.

Tools that used in the previous experiments :

Hex editor

EaseUS data recover

Hash value

Last activity view

You might also like