Linux and Unix recovery
Previous Topic  Next Topic 


Linux and Unix disks are not very common on their own, but are often part of a NAS (Network Attached Storage) system.  This could be a single drive, or part of a RAID 0 or RAID 1 for small systems, and RAID 5 for larger, more secure systems


CnW Recovery will detect the following types of Unix



When detected, the following screen will displayed



The most important sector on a Unix disk is the Superblock.


There are three basic modes to recover Linux disk by



When the forensic option has been purchased useful detail is added to the forensic log.  This includes expected numbers of iNodes, locations of groups etc.


XFS deleted file recovery

It is often stated that it is not possible to recover deleted files from XFS.  This is largely true as unlike NTFS, there is no 'I have been deleted' flag.  Instead the critical iNodes are partially blanks to make them look free, and the tables to state where the iNodes are, and if used are also cleared.  The CnW approach is in five stages



This process will recover files from very damaged XFS disks, and still retain file names, dates and very largely, the complete directory structure.



Reiser Disks


Most Reiser disks are part of the HP Media Vault system.  They can appear as a RAID, or just a single disk.  It is gathered that the system was often sold with a single drive, and then another drive could be added, normally as a JBOD configuration.  The proposed RAID-0 option was never implemented.  For RAID setup see the RAID drives section.


The disk may be read in three ways, Full recovery, scan and raw.  With Full recovery, the first stage is an analysis of all the leaf iNodes to try and establish a directory structure.  The Scan and Raw modes go to a lower level and do not try and read the disk based on the directory structure, though will try and reconstruct the directories.


A useful feature of the program is that it will still work even when the main Superblock herader is missing.  This header is normally at sector 0x80 of the partition, and is recognised by the string ReIsEr2ER at location 0x34 of the block.


Recover All or Recover Selected


Not all configurations can operate with Recover selected.  If Recover All is used and onl;y certain files are required, the recommendation is to use the file filter to select filesbased maybe on name, file type or date..

It is intended to support recover Selected for all Full Recover modes of operation, but scanned modes will rely of the file filter.