{"id":3456,"date":"2018-08-10T01:47:39","date_gmt":"2018-08-09T17:47:39","guid":{"rendered":"https:\/\/www.bytebot.net\/blog\/?p=3456"},"modified":"2018-08-10T01:47:39","modified_gmt":"2018-08-09T17:47:39","slug":"thumb-drive-data-recovery","status":"publish","type":"post","link":"https:\/\/www.bytebot.net\/blog\/archives\/2018\/08\/10\/thumb-drive-data-recovery","title":{"rendered":"Thumb drive data recovery"},"content":{"rendered":"<p>I haven&#8217;t done any data recovery or data rescue work in sometime (the last time was on Linux, with a combination of <code>dd<\/code>, <code>ddrescue<\/code>, and some throwaway code to parse JPGs &#8211; it was a Compact Flash card that needed saving). This time, all I had was macOS, a 16GB thumb drive, and the files were someone&#8217;s life&#8217;s work, which were more than just JPGs but also AI (adobe illustrator), DOC, XLS, PDF, TTF, etc. files. <\/p>\n<p>So via Homebrew, I installed <code>ddrescue<\/code> again. A command like <code>ddrescue -v -n -c 4096 \/dev\/disk2 helena.dmg helena.log<\/code> seemed to work. On macOS, <code>fdisk<\/code> totally couldn&#8217;t get me anything useful and if I ran <code>diskutil list<\/code> the output would be as follows:<\/p>\n<pre><code>\/dev\/disk2 (external, physical):\n   #:                       TYPE NAME                    SIZE       IDENTIFIER\n   0:                                                   *15.5 GB    disk2\n<\/code><\/pre>\n<p>For good measure I wanted to also make an image via <code>dd<\/code>, <code>dd if=\/dev\/disk2 conv=sync,noerror bs=4096 of=helena.img<\/code>. It was clearly throwing many errors, an example of which:<\/p>\n<pre><code>13399375872 bytes transferred in 1263.864380 secs (10601910 bytes\/sec)\ndd: \/dev\/disk2: Input\/output error\ndd: \/dev\/disk2: Input\/output error\n<\/code><\/pre>\n<p>The real problem was mounting either the DMG or the IMG. On Linux you have this option to loopback mount a file; on macOS this isn&#8217;t quite there. There is <code>hdiutil<\/code> but frankly, this doesn&#8217;t work if there is no partition record. I tried to mount it using <code>hdiutil attach -noverify -nomount helena.img<\/code> but that didn&#8217;t work to then do a <code>diskutil mountDisk<\/code>. <\/p>\n<p>Then&#8230; I found a tool: <a href=\"https:\/\/www.cgsecurity.org\/wiki\/PhotoRec\">PhotoRec<\/a>. I wouldn&#8217;t have to write something to parse the magic numbers and extract files. PhotoRec <em>just works<\/em>. It parsed the IMG file, and spat out plenty of files to look at. Recovery was generally full. <\/p>\n<p>For reference, on Linux, there are some good resources: <a href=\"https:\/\/major.io\/2010\/12\/14\/mounting-a-raw-partition-file-made-with-dd-or-dd_rescue-in-linux\/\">Mounting a raw partition file made with dd or dd_rescue in Linux<\/a>, and <a href=\"https:\/\/www.technibble.com\/guide-using-ddrescue-recover-data\/\">Guide to Using DDRescue to Recover Data<\/a>. From a forensic standpoint, <a href=\"https:\/\/github.com\/aburgh\/Disk-Arbitrator\">Disk-Arbitrator<\/a> looks like a good tool as well.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I haven&#8217;t done any data recovery or data rescue work in sometime (the last time was on Linux, with a combination of dd, ddrescue, and some throwaway code to parse JPGs &#8211; it was a Compact Flash card that needed saving). This time, all I had was macOS, a 16GB thumb drive, and the files [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"jetpack_post_was_ever_published":false},"categories":[1503],"tags":[767,1939,768,4,1883,1938],"class_list":["post-3456","post","type-post","status-publish","format-standard","hentry","category-tech","tag-data-recovery","tag-data-rescue","tag-ddrescue","tag-linux","tag-macos","tag-photorec"],"jetpack_publicize_connections":[],"jetpack_shortlink":"https:\/\/wp.me\/p4vJD-TK","jetpack_sharing_enabled":true,"jetpack-related-posts":[],"amp_enabled":true,"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/www.bytebot.net\/blog\/wp-json\/wp\/v2\/posts\/3456","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.bytebot.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.bytebot.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.bytebot.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.bytebot.net\/blog\/wp-json\/wp\/v2\/comments?post=3456"}],"version-history":[{"count":1,"href":"https:\/\/www.bytebot.net\/blog\/wp-json\/wp\/v2\/posts\/3456\/revisions"}],"predecessor-version":[{"id":3457,"href":"https:\/\/www.bytebot.net\/blog\/wp-json\/wp\/v2\/posts\/3456\/revisions\/3457"}],"wp:attachment":[{"href":"https:\/\/www.bytebot.net\/blog\/wp-json\/wp\/v2\/media?parent=3456"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.bytebot.net\/blog\/wp-json\/wp\/v2\/categories?post=3456"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.bytebot.net\/blog\/wp-json\/wp\/v2\/tags?post=3456"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}