|
Home > Support Home > Articles > Performing the Crossover Network Cable Acquisition
Performing the Crossover Network Cable Acquisition
- Make sure the subject machine is configured to boot from the floppy as follows:
- Physically unplug all the hard drives before turning on the computer.
- Power on and run the BIOS setup routine to ensure that the computer is set to boot from the floppy drive (drive A:) if the ENBD is used, or the CD ROM drive if the EnCase Boot CD is used. To access the BIOS setup, you will need to press a specific key sequence repeatedly as soon as the power comes on. On most IBM compatible PCs, the key is [F1] or [Delete]. Compaq computers often use the [F10] key. If possible, check the computer's documentation. There is usually a message flashed on the power splash-screen indicating which key to press to access the BIOS setup.
- In the BIOS, look for the boot order section. After setting the BIOS to boot from the appropriate device with the boot diskette or CD in the drive and the hard drives still disconnected, reboot the computer to confirm that it does.
- After confirming that the computer boots from the correct device, turn off the computer.
- Reconnect the hard drives and reboot the computer with the media still in the drive.
- Connect the subject computer to the storage computer via the crossover cable.
- Boot the subject computer with the appropriate EnCase Network Boot Disk.
- The ENBD displays the following menu options on startup:
- Network Support - Loads the appropriate menu system for crossover acquisition
- USB - Acquisition (no drive letter assigned) - Loads DOS USB drivers to allow the acquisition of a USB-connected device
- USB - Destination (drive letter assigned) - Loads DOS USB drivers to allow storage to a USB-connected device
- Clean boot - Loads similar to the barebones boot disk to do a direct DOS acquisition
- From the menu, select AUTO to allow the ENBD to detect the NIC, or select MANUAL to load the packet driver manually. If AUTO is selected, you are prompted to press any key to accept the drivers, at which point EnCase launches and automatically runs in Network Server mode.
- If the driver is loaded manually, choose ENCASE from the menu to launch EnCase. You can also run EnCase to do a direct DOS acquisition by typing EN.EXE at the command prompt.

EnCase for DOS user screen
- Put EnCase for DOS in Server mode.
- Choose Server. The subject machine should now be running in Server mode, displaying a message stating Waiting to connect...
- Boot the forensic PC into Windows.
- If your forensic computer is using Windows XP Service Pack 2 or Windows 2003, Configure the Windows firewall as follows:
- From the Windows Start button, select Settings, then choose Windows Firewall in the Control Panel.

Windows Firewall control panel
- By default, the Firewall is set to [On]; the Don't allow exceptions box should be unchecked. If it is set to [Off], Windows Firewall has been turned off and will not interfere with any functionality, and you can skip this process. If the Firewall is on, click on the Exceptions tab at the top of the window.

Windows Firewall Exceptions tab
- Click on the [Add Program…] button

Adding an exception
- Find EnCase in the list showing in the Programs: window and click to select it, or click on the [Browse…] button to find the EnCase executable so that it shows in the Path: field.
For v4, the default path is: C:\Program Files\EnCase4
For v5, the default path is: C:\Program Files\EnCase5
- Click on the [OK] button.
- Click on the [OK] button in the main Windows Firewall button to allow the crossover preview\acquisition.
- You will also need to configure your IP Address as follows:
- Right-click on My Network Places and select Properties.
- Right-click on Local Area Connection and select Properties.
- Double-click the TCP/IP protocol.
- Enter a fixed IP address (such as 10.0.0.50) in the IP Address tab.
- Enter a sub-net mask of 255.255.255.0.
- Click on the Advanced button
- Click on the DNS Tab
- Remove all of the DNS server addresses
- Remove all of the DNS suffixes

Removing DNS Servers and Suffixes
- Click on the WINS Tab
- Remove all of the WINS addresses

Removing WINS addresses
- Click on the [OK] button.
- Launch EnCase for Windows.
- Click the [ADD device] button on the top toolbar.
- Place a blue check in the box to the left of Network Crossover and click [Next]

Selecting Network Crossover as Device to Preview
- Blue check the Drive that you wish to acquire and click [Next]

Choosing device on suspect system to preview
- Click [Finish] at the Preview Devices Dialog Box

Preview devices dialog box
- Now you are successfully previewing the suspect's system through the crossover cable.

Previewing a device over the crossover cable
- EnCase overlays a blue triangle in the lower right corner of the device icon to indicate that the device is live.

Blue triangle indicator for live devices
- Now you can right click the Device and choose [Acquire]
- Add any after acquisition options and click [Next]

After Acquisition Options
- Fill in all required and any optional information and click [Finish]

Filling out Acquisition Parameters
- EnCase will now begin acquiring over the network cable.
|
|
| |
|
| © 2002-2007 Guidance Software, Inc. All Rights Reserved.
Privacy Statement |
Historical Information |
Contact Us |
Careers |
Mailing List |
Resellers
|
|