Bios Password

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Saturday, August 8, 2009

Mounting VHD files in Windows for fun and exploration

Posted on 12:08 PM by Unknown

This past week I was able to find a “smidgen” of time at work to apply myself on practicing some system-capture work with a forensic LiveCD.  More on that in a upcoming post.

Once I had my dd image file, I then had a number of Windows tools that allowed me to mount it and access/view it for “examination” practice.  Sure, I know that’s old-hat for your forensics professionals but it is cool and useful even to us system admins.

I routinely acquire and “on-line/off-line” mount ImageX WIM’s and can extract files, modify files in the WIM, and perform other actions.  Sure, because it is a file-based image, it isn’t a forensics level sector-based image but if some WIM’s were captured off a suspect system, these techniques would allow easy review and exploration of the contents.  Standard stuff.

That got me thinking; what options exist for mounting VHD files? 

VHD files can be quite interesting.  Not only do they contain “sector” remnants when items are moved/deleted internally to the VHD, but depending on how the VHD was created, it might even inadvertently have captured unused sector information from the original host physical device it was created on.

Or suppose a target was doing something tricky like dual booting Windows 7 on Vista via VHD file (or on Win7 for that matter).  Or maybe they are particularly geeky and attempting to evade a footprint by Running Windows from a USB flash drive via a VHD file (Hyper-V Server in that case).  Probably not a very common (or easy) thing to do but technically it looks possible.  And Vista/Win7 use the VHD format for “Windows Complete PC Backup and Restore” images; for more info see these Vista and Win7 links.

If the incident responder captured the VHD file either as part of a larger system capture or off a USB drive, they could examine the contents forensically at the sector-level, or they could install Virtual PC/Hyper-V and then try loading/running it there.  But what if they wanted to really explore the “system” or VHD file contents “natively”.

Could it be mounted to a Windows system like we can mount WIM files for examination and review?

It appears so!

The easiest method seems to be to just have a Windows 7 system around handy.  VHD mounting is supported natively in Windows 7 (and Vista with a few tweaks).

  • WIM tool enhancements and Fiddling with VHD’s – Grand Stream Dreams Blog

  • Virtual Hard Disk - Create and Attach VHD - Windows 7 Forums

  • Mount, attach and create VHD files in Windows Vista and Windows 7 – 4sysops blog

  • VHDMount without VHDMount – Dave Northey’s Blog

But maybe you want alternatives?

OK!  Try these on for size.

  • Gizmo Drive – freeware – Amazing utility that contains support for Win2K-Win7 builds.  Allows you to mount ISO,BIN, CUE, NRG files to a virtual CD-ROM drive BUT also allows you to mount VHD files as a virtual drive! Also supports mounting of IMG files to a virtual drive.  Supports mount/unmount commands from Windows Shell and command line.  32/64 bits both supported.  A very headache-free solution in a can.

  • WinMount – commercial ($) - Mount rar, zip, DVD, CD, HDD images (VHD, VDI, and VMDK) as read-only or writeable mode. 32/64 bit supported.

“What” you say?  You want to do it the hard-way in XP/Vista because you just don’t trust such a simple solution and you don’t have a Windows 7 system laying around your work-bench?

Fine.  Be that way.

Be aware that I’m not responsible for any global-warming, polar ice-shelf melting, or scrambling of your own system if you proceed! M’kay?  (It probably will be ok…)

The final trick involves using a Virtual Server tool called VHDmount to mount the VHD file directly into your host Windows OS.

Because this is some serious voodoo, I’m providing quite a few links to get you the foundational knowledge to strike-out on your own.

  • Mounting VHD files with VHDMount - Microsoft Virtual Server – Daniel Petri

  • Mounting a Virtual PC disk image with VHDMount in Vista – SharePoint Voodoo Magic blog

  • Offline VHD file mounting on the host operating system with Virtual Server 2005 R2 SP1 Beta 2 - B# .NET Blog

  • Tell me a VHDMount Story (Installing just VHDMount on Windows Vista and then mounting a VHD as a drive letter...) – Greg’s Cool [Insert Clever Name] of the Day

  • Server 2008 Hyper-V: Alternative to VHDMOUNT - NetworkWorld.com Community

  • VHDMOUNT for Hyper-V - Updated Scripts - Ravikanth Chaganti

  • Script Update: Right click to Mount & Dismount Hyper-V VHD - Ravikanth Chaganti

  • How to mount a VHD under Vista by double clicking – Clemens Schotte’s Blog

  • Windows XP/Vista: How to Attach a VHD File - Tech-Recipes

  • Frequently Asked Questions: Virtual Hard Disks in Windows 7 - Microsoft TechNet

Anyone know of any other techniques or utilities to mount a VHD file apart from those mentioned here?

--Claus V.

Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in forensics, hacks, utilities, Virtual PC, virtualization, Windows 7 | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • Finally! Time to Post! New material list
    After a recent text from my bro reminding me it has been since March since I’ve done a blog post, I was finally able to clear the schedule a...
  • Oscar watch Linkpost
    Alvis and Lavie are watching the Oscars tonight and I’m along for the ride. I wasn’t able to come even close to getting out some of the pos...
  • New Year’s Day - First Post 2011
    Same day I came out with my first post after a long drought, I fell upon this article Blogging Seems To Have Peaked, Says Pew Report over a...
  • Utility Gumbo
    There’s a lot in this pot.  Probably something everyone can find to enjoy. I’m serving it up tonight out of the back of the truck on the s...
  • iodd : Multi-boot madness!
    Like many computer technicians and responders, I seem to always have at hand a collection of bootable media; CD’s, DVD’s, USB-HDD’s, flash m...
  • Ubuntu 13.10 Upgrade - Lessons Learned & VIDMA utility found
    A few weeks ago a new release of Ubuntu came out. Naturally that meant it was update time! I have been getting pretty good at this now so ...
  • Interesting Malware in Email Attempt - URL Scanner Links
    Last weekend I spent some time with extended family helping confirm for them that their on-line email account got hacked and had been used t...
  • Windows 8 Linkage: A Bit Behind the Ball
    CC attribution: behind the eight ball by Ed Schipul on flickr . OK. Confession time. I’m more than a bit exhausted this weekend. Besides a...
  • This Week in Security and Forensics: Beware the cake!
    Cube Party! image used with permission from John Walker at "rockpapershotgun.com" Yeah, the cake is a Portal thing.  Let’s d...
  • Windows 8 Linkage: “Passage Public Metro” version
    cc image credit image by david.nikonvscanon on flickr So Claus, where do you stand on Windows 8 at this point? Well, to be honest, I’m re...

Categories

  • Active Directory
  • anti-virus software
  • Apple
  • architecture
  • art
  • AVG
  • Blogger
  • blogging
  • books
  • boot-cd's
  • browsers
  • cars
  • cell-phones
  • cheat sheets
  • Chrome/Chromium
  • command-line interface
  • cooking
  • crafts
  • crazy
  • curmudgeon
  • DHC
  • Dr. Who
  • E-P1
  • Education
  • family
  • Firefox
  • firewalls
  • For the Gentleman
  • forensics
  • Gmail
  • Google
  • graphics
  • hacks
  • hardware
  • humor
  • hurricanes
  • imagex
  • Internet Explorer
  • iOS
  • iPhone
  • iPod
  • iTunes
  • Kindle
  • Learning
  • Link Fest
  • Linux
  • malware tools
  • Microsoft
  • movies
  • music
  • networking
  • NewsFox
  • NFAT
  • Nook
  • Opera
  • organization
  • PDF's
  • photography
  • politics
  • PowerShell
  • recipes
  • Remote Support
  • RSS
  • science
  • Scripting
  • search engines
  • security
  • Shuttle SFF
  • software
  • Texana
  • Thunderbird
  • troubleshooting
  • TrueCrypt
  • tutorials
  • utilities
  • VBscript
  • video
  • Virtual PC
  • virtualization
  • viruses
  • Vista
  • Vista mods
  • wallpapers
  • Win FE
  • Win PE
  • Win RE
  • Windows 7
  • Windows 8
  • Windows Home Server
  • Windows Live Writer
  • Windows Phone
  • writing
  • XP
  • XP mods
  • Xplico

Blog Archive

  • ►  2013 (83)
    • ►  November (8)
    • ►  October (8)
    • ►  September (14)
    • ►  August (6)
    • ►  July (10)
    • ►  June (10)
    • ►  April (11)
    • ►  March (6)
    • ►  February (7)
    • ►  January (3)
  • ►  2012 (96)
    • ►  December (8)
    • ►  November (4)
    • ►  October (9)
    • ►  September (8)
    • ►  August (12)
    • ►  July (4)
    • ►  June (3)
    • ►  May (7)
    • ►  April (13)
    • ►  March (3)
    • ►  February (5)
    • ►  January (20)
  • ►  2011 (41)
    • ►  December (8)
    • ►  November (7)
    • ►  September (4)
    • ►  August (4)
    • ►  July (2)
    • ►  June (6)
    • ►  March (5)
    • ►  February (1)
    • ►  January (4)
  • ►  2010 (69)
    • ►  December (1)
    • ►  October (3)
    • ►  September (2)
    • ►  August (13)
    • ►  July (17)
    • ►  June (3)
    • ►  May (3)
    • ►  April (3)
    • ►  March (11)
    • ►  February (1)
    • ►  January (12)
  • ▼  2009 (177)
    • ►  December (20)
    • ►  November (11)
    • ►  October (7)
    • ►  September (7)
    • ▼  August (21)
      • Utility & Miscellany
      • Network Capture Tools and Utilities
      • Java Silent Install Notes
      • Utility Gumbo
      • Rapid-Fire Security and Response Linkpost
      • Inspiring Designs #2
      • GSD Hurricane Tracking Links – 2009
      • Search & Acquire by File Type Solutions
      • QuickPost: Bootable USB Stick
      • Devio: Remote drive access and acquisition
      • Tip: Managing Flash Cookies
      • Tip: Add Google’s Beta Search to browsers
      • Adobe Tip: Add filename to footer
      • Focus on Forensics Linkfest
      • Blog reboot – version 4.0
      • Around the (MS) Office pool
      • Drop-Dead-Quick Blue Screen of Death Diagnosis Uti...
      • Windows Linkfest Mowdown
      • Browser Linkfest Blowout
      • Mounting VHD files in Windows for fun and exploration
      • Virtual PC and XP Mode Linkage
    • ►  July (17)
    • ►  June (7)
    • ►  May (18)
    • ►  April (9)
    • ►  March (17)
    • ►  February (23)
    • ►  January (20)
  • ►  2008 (35)
    • ►  December (23)
    • ►  November (12)
Powered by Blogger.

About Me

Unknown
View my complete profile