LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 07-09-2023, 06:10 AM   #1
Mantra
Member
 
Registered: Jun 2018
Posts: 57

Rep: Reputation: Disabled
Data recovery - Windows installation


First, apologies if this doesn't belong in the security forum - seemed like the most appropriate to me.

I decided to play around with an old PC and see if I could recover any data from it, more for practice than because I need to.

The PC has Windows on it, has been used for years, and I've just done a "reset Windows" on it.

Fired up Kali in forensic mode. Ran photorec on the drive, it found about a thousand files - mostly text or xml files that seem to be Windows-installation type files, but nothing else.

I'm wondering why I can't find any of the old data. Unless a Windows reset actually writes to the whole drive, but I'd expect it just to do a quick format and replace the MFT/partition table. Any ideas anyone?
 
Old 07-09-2023, 06:22 AM   #2
fatmac
LQ Guru
 
Registered: Sep 2011
Location: Upper Hale, Surrey/Hants Border, UK
Distribution: Mainly Devuan, antiX, & Void, with Tiny Core, Fatdog, & BSD thrown in.
Posts: 5,506

Rep: Reputation: Disabled
A 'reset' usually puts a computer back to 'factory' condition - why not just mount it & take a look at the file system(?).
 
Old 07-09-2023, 06:52 AM   #3
Mantra
Member
 
Registered: Jun 2018
Posts: 57

Original Poster
Rep: Reputation: Disabled
I can mount it, but that shows the current state (which is a fresh installation of windows). I'm trying to see if anything remains of the files that were on it previously, before doing the reset.

The thousand or so files I found with Photorec, are deleted files - all the normal Windows files from the current installation are on there, as well. I'm kind of interested to see if it's possible to find the old files that were on it before doing the reset.

Sorry, realised my first post wasn't clear!
 
Old 07-09-2023, 06:53 AM   #4
syg00
LQ Veteran
 
Registered: Aug 2003
Location: Australia
Distribution: Lots ...
Posts: 21,145

Rep: Reputation: 4124Reputation: 4124Reputation: 4124Reputation: 4124Reputation: 4124Reputation: 4124Reputation: 4124Reputation: 4124Reputation: 4124Reputation: 4124Reputation: 4124
When in doubt, go get it from the horses mouth - here for example.

Note the difference between "reset" and "refresh".
 
Old 07-09-2023, 07:12 AM   #5
Mantra
Member
 
Registered: Jun 2018
Posts: 57

Original Poster
Rep: Reputation: Disabled
It looks like I have indeed fully reformatted it. I'm surprised Windows does that, actually!
 
Old 07-09-2023, 07:20 AM   #6
syg00
LQ Veteran
 
Registered: Aug 2003
Location: Australia
Distribution: Lots ...
Posts: 21,145

Rep: Reputation: 4124Reputation: 4124Reputation: 4124Reputation: 4124Reputation: 4124Reputation: 4124Reputation: 4124Reputation: 4124Reputation: 4124Reputation: 4124Reputation: 4124
I'm not. They actually tried to help by giving the option. You shot yourself in the foot, not them ... :shrug:

We've all learnt the lesson that data can be lost by "playing around".
 
Old 07-10-2023, 10:11 AM   #7
giesbert
Member
 
Registered: Aug 2003
Location: The Netherlands
Distribution: Debian 12
Posts: 57

Rep: Reputation: 12
You have still the option of testdisk.
 
Old 07-10-2023, 01:19 PM   #8
Mantra
Member
 
Registered: Jun 2018
Posts: 57

Original Poster
Rep: Reputation: Disabled
I tried that, but it gave errors about the disk parameters being incorrect, and I didn't persevere. But if the disk has been overwritten with zeroes it probably won't find anything either I guess?
 
Old 07-12-2023, 05:56 AM   #9
giesbert
Member
 
Registered: Aug 2003
Location: The Netherlands
Distribution: Debian 12
Posts: 57

Rep: Reputation: 12
Quote:
Originally Posted by Mantra View Post
I tried that, but it gave errors about the disk parameters being incorrect, and I didn't persevere. But if the disk has been overwritten with zeroes it probably won't find anything either I guess?
A format is not the same as overwrite with zero's. With a normal format only the partition table is overwritten.
testdisk should be able to make some files available again. As long as these files are not overwritten by a new install, or other drive operations.
 
Old 07-12-2023, 06:42 AM   #10
business_kid
LQ Guru
 
Registered: Jan 2006
Location: Ireland
Distribution: Slackware, Slarm64 & Android
Posts: 16,404

Rep: Reputation: 2337Reputation: 2337Reputation: 2337Reputation: 2337Reputation: 2337Reputation: 2337Reputation: 2337Reputation: 2337Reputation: 2337Reputation: 2337Reputation: 2337
If you're desparate for the stuff, with a spinning rust drive, there is the option shred was designed to prevent. Residual magnetism hangs about, so stuff can be reconstructed by detecting this and resetting it. It's probably a forensic professional job.
 
Old 07-12-2023, 01:47 PM   #11
Mantra
Member
 
Registered: Jun 2018
Posts: 57

Original Poster
Rep: Reputation: Disabled
I might have another play around with testdisk in that case, although I thought photorec worked on a similar basis. And just to clarify so I don't mislead anyone - the data isn't especially important - this is more just an opportunity to see what's possible and how much I can recover. I think I have all my important data backed up... although saying that, I haven't tested my backups for a while so I should do that too!
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: 5 Best Data Recovery Tools For Linux To Recover Data Or Deleted Partitions LXer Syndicated Linux News 0 04-18-2015 02:32 PM
Linux rescue disk for data recovery of data on windows laptop with corrupt os Jonjo-k Linux - Newbie 10 01-04-2014 06:00 PM
[SOLVED] Combining anti-virus + data recovery + image recovery? littlebigman Linux - Software 8 08-12-2010 02:39 AM
Linux recovery of Windows workstations - using baremetal recovery Reefcrazed Linux - Software 20 01-06-2009 05:15 AM
LXer: Linux Data Recovery on Windows - Is possible through Disk Doctors Linux Recovery Software LXer Syndicated Linux News 0 10-22-2006 12:21 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 07:21 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration