VMworld and Forensics
VizionCore and PHD produce backup tools that do block level backups of VMs that are verified via checksums with the originally. If these checksums in use are SHA1 checksums then the full vmdk backup could be forensically sound. In addition to this, full VM backups using these tools can include a memory image of the currently running VM.
This implies that backup tools which are not normally used by forensic scientists could be used in the case of VMware ESX hosts.
The following commands can get this information as well:
$WID=`vm-support -x | grep vmname | awk '{print $1}'`
vm-support -X $WID
The -x option grabs the world id of the VM and the -X grabs the memory image. You can do the same thing with a snapshot as well.
However, it does say that grabbing the memory image in this way could mutate the VM in some undisclosed way.
More research may be needed for these steps but the ability to create snapshots and grab the memory image of a running VM increase the abilities of forensic scientists. In addition, with backups being block level backups, backups can now be analyzed as well.
Sign up for ITworld's Daily newsletter
Follow ITworld on Twitter @IT_world
Esther Schindler
If the comments are ugly, the code is ugly
claird
SVG a graphics format for 21st century
pasmith
Take Chrome OS for a test spin
Sandra Henry-Stocker
Solaris Tip: Have Your Files Changed Since Installation?
jfruh
Android fragments vs. the iPhone monolith
mikelgan
What Gizmodo missed about the Pro WX Wireless USB disk drive
Sidekick: The Good News & the Bad News
Either way you look at it Microsoft Data Center management did not follow standards or best practices in this failure. In which case it makes me wonder more about the outsourcing of corporate data much less personal data.
- mburton325
Join the conversation here
Quick, practical advice for IT pros. Made fresh daily.
Want to cash in on your IT savvy? Send your tip to tips@itworld.com. If we post it, we'll send you a $25 Amazon e-gift card.













