Documentos de Académico
Documentos de Profesional
Documentos de Cultura
Forensics
USB Basics
History
Hardware
Software
History
Non-universal serial, PS/2 ports, & LPT
Hardware
Hot pluggable
Name
Cable color
Description
VBUS
Red
+5 V
White
Data
D+
Green
Data +
GND
Black
Ground
Software
Automatic configuration
No settable jumpers
Enumeration
Audio
Mass Storage
Software
Filesystems
Windows
Hardware
Software
Must:
Detect communication directed at drive
Exchange data
Filesystems
NTFS
TrueFFS
ExtremeFFS
JFFS
YAFFS
Connecting a Drive
Device is connected
Hub detects
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\
StorageDevicePolicies\ WriteProtect
Blocks writing to ALL USB devices
Commercial write-blockers
Forensics
Flash Drive as Memory
Most chips not even close to high-speed USB speed (480 Mbps)
Chip Choice
16 KB RAM
2 SPI slave and 1 SPI master interfaces
Easy-to-use IDE
A Simple Duplicator
Command Block
} CB_FORMAT_UNIT;
READ_FORMAT_CAPACITIES=0x23,
FORMAT_UNIT=0x4, //required
REQUEST_SENSE=0x03, //required
INQUIRY=0x12, //required
SEND_DIAGNOSTIC=0x1D, //required
MODE_SELECT6=0x15,
START_STOP_UNIT=0x1B,
MODE_SELECT10=0x55,
SYNCHRONIZE_CACHE10=0x35,
MODE_SENSE6=0x1A,
TEST_UNIT_READ=0x00, //required
MODE_SENSE10=0x5A,
VERIFY10=0x2F,
READ6=0x08, //required
WRITE6=0x0A, //required
READ10=0x28, //required
WRITE10=0x2A,
READ12=0xA8,
WRITE12=0xAA
READ_CAPACITY10=0x25, //required
REPORT_LUNS=0xA0, //required
References
USB Complete: The Developers Guide (4th ed.) by Jan
Axelson
Questions?