Open swappage opened 3 years ago
A quick update i've made the same test using the sleuthkit windows binaries 4.10.2 and the results are correct (same as with 4.6.7, so i wonder if this is in any way related to a filesystem parsing issue or something more autopsy related.
Hello, i'm having a pretty serious consistency problem when analyzing an ext4 filesystem from a samsung S7 edge android device internal emmc storage.
Informations about the software versions used:
The symptom is that certain files size and content are wrongly returned by autopsy and content is therefore not parsed properly. I noticed it because i suspected something was wrong with some whatsapp database files that i knew for sure were filled with data while the size reported by autopsy itself was 0 bytes allocated.
as you can see in the image the msgstore.db file is 0 bytes in size
This looked very strange so i double checked using fls from the sleuthkit and here is the result
as you can see the file size is different. the ones from TSK are correct, i can export the allocated file and parse it properly while autopsy fails.
I'm very worried that this problem can also affect other files on the same image but i can't know for sure
here are the information resturned about the partition by fsstat
and here are the informations returned by autopsy, at a glance they look the same
unfortunately i cannot share the image as this is a real evidence, reason i know this might be VERY problematic to troubleshoot.