Dell PERC Raid Array

From: Bill Moylan (billyfmat_private)
Date: Wed Aug 20 2003 - 14:12:33 PDT

  • Next message: J: "Windows forensics with Linux analysis machine"

    I came across this Dell 1600 server in the field and was unable to make an 
    image of it. (of course it would be in the field). I booted with Knoppix 
    and the software identified a "Megaraid" and a /dev/sda disk with a size of 
    36GB. This was what was expected as the Admin advised it was a 3-18GB drive 
    RAID 5. With one of the drives used for parity, the 36GB was consistent. I 
    attempted to image the "physical" /dev/sda, hoping to get the entire device 
    with the2 included partitions. I tried dumping the data with "dd 
    if=/dev/sda conv=noerror |split -b 2048000000 - /mnt/sdb1/imagefiles." The 
    sdb1 is a USB 2 drive (unfortunately unsupported on the server device, so 
    running as USB 1). Due to the slow speed of the drive, the setup was left 
    working overnight. The imaging failed at about 10G, having created 4 2GB 
    file chunks and part of a third. Since I will have to return to finish this 
    I would like some help correcting my process. I intend to bring a 
    USB2/Firewire card with me to deal with the speed issue, but am wondering 
    if I should try to image the entire 36GB or image the 2 partitions 
    individually.
    
    Any help is appreciated
    
    Bill Moylan
    
    
    -----------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    



    This archive was generated by hypermail 2b30 : Wed Aug 20 2003 - 17:26:25 PDT