Professional Documents
Culture Documents
• “dfr-02-fat.dd”
MBR – Phy Sec 0 Partition 1:
00 02 03 00 01 07 06 01 80 00 00 00 00 40 00 00
Partition 2:
00 07 07 01 06 1B 16 05 80 40 00 00 00 00 01 00
__ – bootable volume
__ __ __– Starting of volume written in CHS format
__ – Partition Type
__ __ __– End of volume written in CHS format
__ __ __ __ – Relative start sector of volume in LBA
__ __ __ __– total sectors
VBR of the Partition2
VBR of partition2 resides on “phy sec = 16512”
F8 FF FF FF 00 00 04 00 FF FF 00 00 00 00 08 00
FF FF 00 00 00 00 0C 00 FF FF 00 00 00 00 00 00
0 1 2 3 4 5 6 7
F8FF FFFF 0000 0400 FFFF 0000 0000 0800
8 9 10 11 12 13 14 15
FFFF 0000 0000 0C00 FFFF 0000 0000 0000
The file using cluster 3 will also use cluster 4
Root directory of Partition 2 (Directory Entry)
41 4C 43 4F 52 20 20 20 54 58 54|20|00|64|66 73|99 3F|21 26|00 00|20 10|21 26|03 00|00 08 00 00|
0-10 (8.3 name) 11 attribute 12 Reserved 13 Ctime (in 10ms)
ALCOR.TXT 20 00 64 -> 100 = 1.00
14-15 Ctime (h/m/s) 16-17 Cday Y/M/D 18-19 Aday 20-21 hbyte
cluster
66 73 01110 011011 99 3F 0011111 1100 21 26 0010011 0001 00 00
00110 11001 00001
Hour = 14 Minute = 27 Year = 1980 + 31 = 2011 Year = 1980 + 19 = 1999
Second = 6 x 2 +1 = 7 Month = 12 , Day = 25 Month = 1, Day =1
22-23 Wtime 24-25 26-27 lbyte 28-31 size
Wday cluster
20 10 00010 000001 21 26 03 00 00 08 00 00
00000 3 2048 (byte)
Hour = 2, Minute = 1
Second = 0 x 2 = 0
• NTFS_2GB.E01
Go to $MFT, go to offset 58368 (57x1024).