Jump to content











Photo
- - - - -

EWF Proxy for ImDisk

ewf proxy imdisk

  • Please log in to reply
7 replies to this topic

#1 erwan.l

erwan.l

    Platinum Member

  • Developer
  • 3041 posts
  • Location:Nantes - France
  •  
    France

Posted 20 July 2014 - 08:26 PM

Hi,

 

Following the ImDisk example provided by v77 here, I gave it a go for an EWF proxy for ImDisk.

 

Find here attached the proxy.dll binary along with its source code (in delphi).

 

To launch the proxy : devio --dll=proxy.dll;dllopen shm:test_proxy c:\test.e01.

To use the proxy from ImDisk : imdisk -a -t proxy -o shm -o ro -f test_proxy -m Z: .

 

Note the RO flag as EWF can only be mounted as read only.

 

Regards,

Erwan

Attached Files



#2 erwan.l

erwan.l

    Platinum Member

  • Developer
  • 3041 posts
  • Location:Nantes - France
  •  
    France

Posted 03 May 2015 - 05:28 PM

A new version build with latest libewf.

 

Built so that it depends on msvcrt.dll and no longer on msvcrtxxx.dll.

 

Proxy.dll size down to 90k.

 

Zip contains latest devio.exe and a batch example to launch devio and imdisk in one go.

  •  

 

Attached Files



#3 Olof Lagerkvist

Olof Lagerkvist

    Gold Member

  • Developer
  • 1448 posts
  • Location:Borås, Sweden
  •  
    Sweden

Posted 03 May 2015 - 06:25 PM

Thanks, but either I am doing something wrong or there is something wrong with this proxy_EWF.zip. I can't seem to decompress it.

#4 erwan.l

erwan.l

    Platinum Member

  • Developer
  • 3041 posts
  • Location:Nantes - France
  •  
    France

Posted 03 May 2015 - 06:37 PM

Thanks, but either I am doing something wrong or there is something wrong with this proxy_EWF.zip. I can't seem to decompress it.

 

new zip file.

 

i have the feeling win8.1 is killing all my zip files these days...

 

 

Attached Files



#5 Olof Lagerkvist

Olof Lagerkvist

    Gold Member

  • Developer
  • 1448 posts
  • Location:Borås, Sweden
  •  
    Sweden

Posted 03 May 2015 - 06:49 PM

Works perfectly. Thanks!

But in this case I see quite a lot of messages like "Read request - size:4096 offset:nnnn".



#6 Zoso

Zoso

    Silver Member

  • Advanced user
  • 640 posts
  •  
    Isle of Man

Posted 03 May 2015 - 06:50 PM

hi erwan.l & Olaf,

first I just want to say you guys (incl. Wonko also) are amazing to watch as these new developments come to be here at reboot.pro


for the record though (and the folks who are searching "EWF") this is not Embedded Write Filter (EWF) is it?

following the other threads that youve been working in I noticed this different EWF. can you clarify a bit on that?

Thanks

#7 erwan.l

erwan.l

    Platinum Member

  • Developer
  • 3041 posts
  • Location:Nantes - France
  •  
    France

Posted 03 May 2015 - 06:52 PM

hi erwan.l & Olaf,

first I just want to say you guys (incl. Wonko also) are amazing to watch as these new developments come to be here at reboot.pro


for the record though (and the folks who are searching "EWF") this is not Embedded Write Filter (EWF) is it?

following the other threads that youve been working in I noticed this different EWF. can you clarify a bit on that?

Thanks

 

EWF as in Expert Witness Compression Format.

http://www.forensics...age_file_format



#8 erwan.l

erwan.l

    Platinum Member

  • Developer
  • 3041 posts
  • Location:Nantes - France
  •  
    France

Posted 03 May 2015 - 06:53 PM

Works perfectly. Thanks!

But in this case I see quite a lot of messages like "Read request - size:4096 offset:nnnn".

 

Indeed, i did not remove yet the debugging messages.

I had been using these messages for specific debug purposes but no longer need there.







Also tagged with one or more of these keywords: ewf, proxy, imdisk

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users