Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #189295 > unrolled thread
| Started by | bd <bdebreil@teaser.fr> |
|---|---|
| First post | 2017-11-26 11:10 +0100 |
| Last post | 2017-11-27 03:10 +0100 |
| Articles | 12 — 9 participants |
Back to article view | Back to linux.debian.user
Need Help restoring a filesystem on an external drive WD 'My Book' bd <bdebreil@teaser.fr> - 2017-11-26 11:10 +0100
Re: Need Help restoring a filesystem on an external drive WD 'My Book' arne <sp113438@telfort.nl> - 2017-11-26 11:20 +0100
Re: Need Help restoring a filesystem on an external drive WD 'My Book' Bernard <bdebreil@teaser.fr> - 2017-11-28 17:20 +0100
Re: Need Help restoring a filesystem on an external drive WD 'My Book' "Thomas Schmitt" <scdbackup@gmx.net> - 2017-11-28 19:50 +0100
Re: Need Help restoring a filesystem on an external drive WD 'My Book' "Brian J. Oney" <brian.j.oney@googlemail.com> - 2017-11-28 20:40 +0100
Re: Need Help restoring a filesystem on an external drive WD 'My Book' Bernard <bdebreil@teaser.fr> - 2017-12-03 19:10 +0100
Re: Need Help restoring a filesystem on an external drive WD 'My Book' "Thomas Schmitt" <scdbackup@gmx.net> - 2017-12-03 20:10 +0100
Re: Need Help restoring a filesystem on an external drive WD 'My Book' David Wright <deblis@lionunicorn.co.uk> - 2017-12-04 02:00 +0100
Re: Need Help restoring a filesystem on an external drive WD 'My Book' "Thomas Schmitt" <scdbackup@gmx.net> - 2017-11-26 11:50 +0100
Re: Need Help restoring a filesystem on an external drive WD 'My Book' "Alexander V. Makartsev" <avbetev@gmail.com> - 2017-11-26 21:10 +0100
Re: Need Help restoring a filesystem on an external drive WD 'My Book' David Christensen <dpchrist@holgerdanske.com> - 2017-11-26 22:40 +0100
Re: Need Help restoring a filesystem on an external drive WD 'My Book' Richard Hector <richard@walnut.gen.nz> - 2017-11-27 03:10 +0100
| From | bd <bdebreil@teaser.fr> |
|---|---|
| Date | 2017-11-26 11:10 +0100 |
| Subject | Need Help restoring a filesystem on an external drive WD 'My Book' |
| Message-ID | <uQ22S-6jt-1@gated-at.bofh.it> |
[Multipart message — attachments visible in raw view] — view raw
Hi to Everyone, My WD P/N : WD10000H 1Q S/N : WCAU4D 164675 is about 4 or 5 years old. It is an external drive using external power supply. At start, I had formatted it in ext3, so that I 'd be able to storage videofiles larger than 2 Gb. Since then, I storaged a number of files in several directories, subdirectories etc.. I never had any problem until now. This drive no longer mounts. It does not mount automatically as it used to, and I don't know how to mount it manually. My other similar drives mount on /dev/sdb1 or /dev/sr0... depending on to which computer I mount it. In case it doesn't automatically mount, I just type : #mount /dev/sdb1 /media/bd/ext and it works but right now I don't know for sure the device name to mount. If I list my /dev directory using ls -lt, I can see what new device appears in the list whenever I plug my external drive. It shows 'sdb'. Not 'sdb1' as for other external drives, just 'sdb'. If now I type : # mount /dev/sdb /media/bd/ext this gets the external drive to react : the light goes up and down for awhile, and then I get this message : 'you must specify the filesystem' But, if I try : # mount -t ext3 /dev/sdb /media/bd/ext I get this : 'wrong fs type, bad option, bad superblock on /dev/sdb…' same result if I try mounting on 'fat', 'msdos'… filesystems, but I doubt if there are any FAT or msdos space left on this device since I had reformated it to ext3. At last, I tried : # fsck /dev/sdb (the external drive starts to light, then : 'fsck ext2 : superblock invalid. Trying to backup blocks fsck ext2 : bad magic number in superblock while trying to open /dev/sdb Now, if I type : cat /proc/scsi/scsi I get this : scsi0 ATA MAXTOR STM scsi1 ATA MAXTOR STM scsi5 WD My Book Direct Access /etc/fstab does not show any sdb device How am I to get this drive back to operation, or, at least, to recuperate the datafiles that are stored in that WD external drive ? Thanks in advance to tell me what diagnosis and repair tools I could use Bernard
[toc] | [next] | [standalone]
| From | arne <sp113438@telfort.nl> |
|---|---|
| Date | 2017-11-26 11:20 +0100 |
| Subject | Re: Need Help restoring a filesystem on an external drive WD 'My Book' |
| Message-ID | <uQ2cx-6n0-1@gated-at.bofh.it> |
| In reply to | #189295 |
> How am I to get this drive back to operation, or, at least, to > recuperate the datafiles that are stored in that WD external drive ? > > Thanks in advance to tell me what diagnosis and repair tools I could > use > > Bernard Hello, TestDisk checks the partition and boot sectors of your disks. It is very useful in forensics, recovering lost partitions. PhotoRec is file data recovery software designed to recover lost pictures from digital camera memory or even Hard Disks.It has been extended to search also for non audio/video headers. Both are in the packet testdisk Hope this helps, Greeting.
[toc] | [prev] | [next] | [standalone]
| From | Bernard <bdebreil@teaser.fr> |
|---|---|
| Date | 2017-11-28 17:20 +0100 |
| Subject | Re: Need Help restoring a filesystem on an external drive WD 'My Book' |
| Message-ID | <uQQM1-5lk-1@gated-at.bofh.it> |
| In reply to | #189296 |
Thanks to All for your advises. Indeed, I most likely have a hardware
problem with this WD external drive. It no longer boots, that is for
sure... But, at most starts it get registered as scsi drive, as reveals
$cat /proc/scsi/scsi
it does most times, not all times. When it does not, I have to unplug
an,d replug it, and it will likely registers. Once registered, it
remains so.
Anyway, for a start I tried 'TestDisk. the test lasted about five hours,
and I copy/paste the log file below. In this text, I pointed out 16
lines that suggest a call to 'e2fsck', each with different paramaters
for -b and -B. Prior to try this, I thought I'd better ask your advices
first.
"e2fsck -b 214990848 -B 4096 device" may be needed
.....
I also noticed such lines :
ext2 blocksize=4096 Large file Sparse superblock, 1000 GB / 931 GiB
and I doubt if I understand what is a 'sparse' superblock
Also, about what the logfile mentions on FAT partitions... I don't think I had a fat partition left ever since I had, about 4-5 years ago,reformatted the whole drive to ext2. But there maybe remains of erased FAT partition, as I can't remember whether the reformat that I did was a deep reformat or not.
Now, here is the logfile as its whole :
Using locale 'fr_FR.UTF-8'.
Terminal has only 22 lines
Using locale 'fr_FR.UTF-8'.
Terminal has only 22 lines
Using locale 'fr_FR.UTF-8'.
Mon Nov 27 16:20:47 2017
Command line: TestDisk /log /dev/sdb
TestDisk 6.14, Data Recovery Utility, July 2013
Christophe GRENIER <grenier@cgsecurity.org>
http://www.cgsecurity.org
OS: Linux, kernel 3.13.0-32-generic (#57-Ubuntu SMP Tue Jul 15 03:51:08 UTC 2014) x86_64
Compiler: GCC 4.8
Compilation date: 2013-10-29T01:29:29
ext2fs lib: 1.42.9, ntfs lib: libntfs-3g, reiserfs lib: none, ewf lib: none
Hard disk list
Disk /dev/sdb - 1000 GB / 931 GiB - CHS 121601 255 63, sector size=512 - WD My Book, FW:1028
Partition table type (auto): Mac
Disk /dev/sdb - 1000 GB / 931 GiB - WD My Book
Partition table type: Mac
Analyse Disk /dev/sdb - 1000 GB / 931 GiB - CHS 121601 255 63
check_part_mac failed for partition type AF
Current partition structure:
1 P partition_map 1 63 63
2 P Free 64 262207 262144
3 P HFS 262208 1953525151 1953262944
3 P HFS 262208 1953525151 1953262944
4 P Free 1953525152 1953525167 16
search_part()
Disk /dev/sdb - 1000 GB / 931 GiB - CHS 121601 255 63
Linux 262208 1953525151 1953262944
ext2 blocksize=4096 Large file Sparse superblock, 1000 GB / 931 GiB
interface_write()
P Linux 262208 1953525151 1953262944
search_part()
Disk /dev/sdb - 1000 GB / 931 GiB - CHS 121601 255 63
Linux 262208 1953525151 1953262944
ext2 blocksize=4096 Large file Sparse superblock, 1000 GB / 931 GiB
recover_EXT2: "e2fsck -b 32768 -B 4096 device" may be needed
Linux 262208 1953525151 1953262944
ext2 blocksize=4096 Large file Sparse superblock Backup superblock, 1000 GB / 931 GiB
recover_EXT2: "e2fsck -b 98304 -B 4096 device" may be needed
Linux 262208 1953525151 1953262944
ext2 blocksize=4096 Large file Sparse superblock Backup superblock, 1000 GB / 931 GiB
recover_EXT2: "e2fsck -b 163840 -B 4096 device" may be needed
Linux 262208 1953525151 1953262944
ext2 blocksize=4096 Large file Sparse superblock Backup superblock, 1000 GB / 931 GiB
recover_EXT2: "e2fsck -b 229376 -B 4096 device" may be needed
Linux 262208 1953525151 1953262944
ext2 blocksize=4096 Large file Sparse superblock Backup superblock, 1000 GB / 931 GiB
recover_EXT2: "e2fsck -b 294912 -B 4096 device" may be needed
Linux 262208 1953525151 1953262944
ext2 blocksize=4096 Large file Sparse superblock Backup superblock, 1000 GB / 931 GiB
recover_EXT2: "e2fsck -b 819200 -B 4096 device" may be needed
Linux 262208 1953525151 1953262944
ext2 blocksize=4096 Large file Sparse superblock Backup superblock, 1000 GB / 931 GiB
recover_EXT2: "e2fsck -b 884736 -B 4096 device" may be needed
Linux 262208 1953525151 1953262944
ext2 blocksize=4096 Large file Sparse superblock Backup superblock, 1000 GB / 931 GiB
recover_EXT2: "e2fsck -b 1605632 -B 4096 device" may be needed
Linux 262208 1953525151 1953262944
ext2 blocksize=4096 Large file Sparse superblock Backup superblock, 1000 GB / 931 GiB
recover_EXT2: "e2fsck -b 2654208 -B 4096 device" may be needed
Linux 262208 1953525151 1953262944
ext2 blocksize=4096 Large file Sparse superblock Backup superblock, 1000 GB / 931 GiB
recover_EXT2: "e2fsck -b 4096000 -B 4096 device" may be needed
Linux 262208 1953525151 1953262944
ext2 blocksize=4096 Large file Sparse superblock Backup superblock, 1000 GB / 931 GiB
recover_EXT2: "e2fsck -b 7962624 -B 4096 device" may be needed
Linux 262208 1953525151 1953262944
ext2 blocksize=4096 Large file Sparse superblock Backup superblock, 1000 GB / 931 GiB
recover_EXT2: "e2fsck -b 11239424 -B 4096 device" may be needed
Linux 262208 1953525151 1953262944
ext2 blocksize=4096 Large file Sparse superblock Backup superblock, 1000 GB / 931 GiB
recover_EXT2: "e2fsck -b 20480000 -B 4096 device" may be needed
Linux 262208 1953525151 1953262944
ext2 blocksize=4096 Large file Sparse superblock Backup superblock, 1000 GB / 931 GiB
recover_EXT2: "e2fsck -b 23887872 -B 4096 device" may be needed
Linux 262208 1953525151 1953262944
ext2 blocksize=4096 Large file Sparse superblock Backup superblock, 1000 GB / 931 GiB
recover_EXT2: "e2fsck -b 71663616 -B 4096 device" may be needed
Linux 262208 1953525151 1953262944
ext2 blocksize=4096 Large file Sparse superblock Backup superblock, 1000 GB / 931 GiB
recover_EXT2: "e2fsck -b 78675968 -B 4096 device" may be needed
Linux 262208 1953525151 1953262944
ext2 blocksize=4096 Large file Sparse superblock Backup superblock, 1000 GB / 931 GiB
recover_EXT2: "e2fsck -b 102400000 -B 4096 device" may be needed
Linux 262208 1953525151 1953262944
ext2 blocksize=4096 Large file Sparse superblock Backup superblock, 1000 GB / 931 GiB
FAT differs, FAT sectors=0-8/8
heads/cylinder 4 (FAT) != 255 (HD)
sect/track 17 (FAT) != 63 (HD)
Unknown 1232803376 1232824114 20739 [NO NAME]
FAT12, blocksize=4096, 10 MB / 10 MiB
check_FAT: Unusual media descriptor (0xf0!=0xf8)
heads/cylinder 2 (FAT) != 255 (HD)
sect/track 18 (FAT) != 63 (HD)
Unknown 1248094824 1248097703 2880 [Debian Inst]
FAT12, blocksize=512, 1474 KB / 1440 KiB
Linux 1248097704 1248100583 2880
ext2 blocksize=1024, 1474 KB / 1440 KiB
check_FAT: Unusual media descriptor (0xf0!=0xf8)
heads/cylinder 2 (FAT) != 255 (HD)
sect/track 18 (FAT) != 63 (HD)
Unknown 1248100584 1248103463 2880 [Debian Inst]
FAT12, blocksize=512, 1474 KB / 1440 KiB
check_FAT: Unusual media descriptor (0xf0!=0xf8)
heads/cylinder 2 (FAT) != 255 (HD)
sect/track 36 (FAT) != 63 (HD)
Unknown 1567964760 1567970519 5760 [Debian Inst]
FAT12, blocksize=1024, 2949 KB / 2880 KiB
check_FAT: Unusual media descriptor (0xf0!=0xf8)
heads/cylinder 2 (FAT) != 255 (HD)
sect/track 36 (FAT) != 63 (HD)
Unknown 1695513088 1695518847 5760 [Debian Inst]
FAT12, blocksize=1024, 2949 KB / 2880 KiB
FAT differs, FAT sectors=0-8/8
heads/cylinder 4 (FAT) != 255 (HD)
sect/track 17 (FAT) != 63 (HD)
Unknown 1698249656 1698270394 20739 [NO NAME]
FAT12, blocksize=4096, 10 MB / 10 MiB
check_FAT: Unusual media descriptor (0xf0!=0xf8)
heads/cylinder 2 (FAT) != 255 (HD)
sect/track 18 (FAT) != 63 (HD)
Unknown 1714882408 1714885287 2880 [Debian Inst]
FAT12, blocksize=512, 1474 KB / 1440 KiB
Linux 1714885288 1714888167 2880
ext2 blocksize=1024, 1474 KB / 1440 KiB
check_FAT: Unusual media descriptor (0xf0!=0xf8)
heads/cylinder 2 (FAT) != 255 (HD)
sect/track 18 (FAT) != 63 (HD)
Unknown 1714888168 1714891047 2880 [Debian Inst]
FAT12, blocksize=512, 1474 KB / 1440 KiB
recover_EXT2: "e2fsck -b 214990848 -B 4096 device" may be needed
Linux 262208 1953525151 1953262944
ext2 blocksize=4096 Large file Sparse superblock Backup superblock, 1000 GB / 931 GiB
interface_write()
No partition found or selected for recovery
simulate write!
Interface Advanced
check_part_mac failed for partition type AF
1 P partition_map 1 63 63
2 P Free 64 262207 262144
3 P HFS 262208 1953525151 1953262944
4 P Free 1953525152 1953525167 16
HFS_HFSP_boot_sector
3 P HFS 262208 1953525151 1953262944
Volume header
Bad
Backup volume header
Bad
Sectors are not identical.
HFS_HFSP_boot_sector
3 P HFS 262208 1953525151 1953262944
Volume header
Bad
Backup volume header
Bad
Sectors are not identical.
Superblock Backup superblock
0000 0080a303 ac8d8d0e ........ 00000000 00000000 ........
0008 1547ba00 bcd4e602 .G...... 00000000 00000000 ........
0010 7471a103 00000000 tq...... 00000000 00000000 ........
0018 02000000 02000000 ........ 00000000 00000000 ........
0020 00800000 00800000 ........ 00000000 00000000 ........
0028 00200000 9de01159 . .....Y 00000000 00000000 ........
0030 00e21159 56002400 ...YV.$. 00000000 00000000 ........
0038 53ef0000 01000000 S....... 00000000 00000000 ........
0040 0388dd4b 004eed00 ...K.N.. 00000000 00000000 ........
0048 00000000 01000000 ........ 00000000 00000000 ........
0050 00000000 0b000000 ........ 00000000 00000000 ........
0058 00010000 38000000 ....8... 00000000 00000000 ........
0060 02000000 03000000 ........ 00000000 00000000 ........
0068 6f048c19 5ed54af8 o...^.J. 00000000 00000000 ........
0070 b665401f 92a05116 .e@...Q. 00000000 00000000 ........
0078 00000000 00000000 ........ 00000000 00000000 ........
0080 00000000 00000000 ........ 00000000 00000000 ........
0088 2f6d6564 69612f62 /media/b 00000000 00000000 ........
0090 642f3666 30343863 d/6f048c 00000000 00000000 ........
0098 31392d35 6564352d 19-5ed5- 00000000 00000000 ........
00A0 34616638 2d623636 4af8-b66 00000000 00000000 ........
00A8 352d3430 31663932 5-401f92 00000000 00000000 ........
00B0 61303531 31360000 a05116.. 00000000 00000000 ........
00B8 00000000 00000000 ........ 00000000 00000000 ........
00C0 00000000 00000000 ........ 00000000 00000000 ........
00C8 00000000 0000c503 ........ 00000000 00000000 ........
00D0 00000000 00000000 ........ 00000000 00000000 ........
00D8 00000000 00000000 ........ 00000000 00000000 ........
00E0 00000000 00000000 ........ 00000000 00000000 ........
00E8 00000000 214ef652 ....!N.R 00000000 00000000 ........
00F0 54f54df2 a8d486b3 T.M..... 00000000 00000000 ........
00F8 0bc68920 01000000 ... .... 00000000 00000000 ........
0100 00000000 00000000 ........ 00000000 00000000 ........
0108 0388dd4b 00000000 ...K.... 00000000 00000000 ........
0110 00000000 00000000 ........ 00000000 00000000 ........
0118 00000000 00000000 ........ 00000000 00000000 ........
0120 00000000 00000000 ........ 00000000 00000000 ........
0128 00000000 00000000 ........ 00000000 00000000 ........
0130 00000000 00000000 ........ 00000000 00000000 ........
0138 00000000 00000000 ........ 00000000 00000000 ........
0140 00000000 00000000 ........ 00000000 00000000 ........
0148 00000000 00000000 ........ 00000000 00000000 ........
0150 00000000 00000000 ........ 00000000 00000000 ........
0158 00000000 1c001c00 ........ 00000000 00000000 ........
0160 01000000 00000000 ........ 00000000 00000000 ........
0168 00000000 00000000 ........ 00000000 00000000 ........
0170 00000000 00000000 ........ 00000000 00000000 ........
0178 b0c11301 00000000 ........ 00000000 00000000 ........
0180 00000000 00000000 ........ 00000000 00000000 ........
0188 00000000 00000000 ........ 00000000 00000000 ........
0190 00000000 00000000 ........ 00000000 00000000 ........
0198 00000000 00000000 ........ 00000000 00000000 ........
01A0 00000000 00000000 ........ 00000000 00000000 ........
01A8 00000000 00000000 ........ 00000000 00000000 ........
01B0 00000000 00000000 ........ 00000000 00000000 ........
01B8 00000000 00000000 ........ 00000000 00000000 ........
01C0 00000000 00000000 ........ 00000000 00000000 ........
01C8 00000000 00000000 ........ 00000000 00000000 ........
01D0 00000000 00000000 ........ 00000000 00000000 ........
01D8 00000000 00000000 ........ 00000000 00000000 ........
01E0 00000000 00000000 ........ 00000000 00000000 ........
01E8 00000000 00000000 ........ 00000000 00000000 ........
01F0 00000000 00000000 ........ 00000000 00000000 ........
01F8 00000000 00000000 ........ 00000000 00000000 ........
Interface Advanced
check_part_mac failed for partition type AF
1 P partition_map 1 63 63
2 P Free 64 262207 262144
3 P HFS 262208 1953525151 1953262944
4 P Free 1953525152 1953525167 16
TestDisk exited normally.
arne wrote:
>> How am I to get this drive back to operation, or, at least, to
>> recuperate the datafiles that are stored in that WD external drive ?
>>
>> Thanks in advance to tell me what diagnosis and repair tools I could
>> use
>>
>> Bernard
>>
>
> Hello,
>
> TestDisk checks the partition and boot sectors of your disks.
> It is very useful in forensics, recovering lost partitions.
>
> PhotoRec is file data recovery software designed to recover lost
> pictures from digital camera memory or even Hard Disks.It has been
> extended to search also for non audio/video headers.
>
> Both are in the packet testdisk
>
> Hope this helps,
>
> Greeting.
>
>
>
>
[toc] | [prev] | [next] | [standalone]
| From | "Thomas Schmitt" <scdbackup@gmx.net> |
|---|---|
| Date | 2017-11-28 19:50 +0100 |
| Message-ID | <uQT7b-6Ge-1@gated-at.bofh.it> |
| In reply to | #189370 |
Hi, arne wrote: > and I doubt if I understand what is a 'sparse' superblock It's not a bad sign, as it seems: http://www.nongnu.org/ext2-doc/ext2.html#SUPERBLOCK "The first version of ext2 (revision 0) stores a copy at the start of every block group, along with backups of the group descriptor block(s). Because this can consume a considerable amount of space for large filesystems, later revisions can optionally reduce the number of backup copies by only putting backups in specific groups (this is the sparse superblock feature)." > Command line: TestDisk /log /dev/sdb > ... > 1 P partition_map 1 63 63 Looks like it recognized a GUID partition table (GPT). > 3 P HFS 262208 1953525151 1953262944 This would be the ext filesystem's partition. The following superuser command establishes a read-only loop device which begins at the given block: losetup -o $(expr 262208 '*' 512) -r -f /dev/sdb (Contrary to the man page, losetup -f does not tell me the used device path. I have to run losetup -l | fgrep /dev/sdb to learn that it's /dev/loop0.) > Linux 262208 1953525151 1953262944 > ext2 blocksize=4096 Large file Sparse superblock, 1000 GB / 931 GiB > recover_EXT2: "e2fsck -b 32768 -B 4096 device" may be needed This is probably the normal superblock in that partition. But running e2fsck might cause the end of the remaining data in the filesystem. I'd try to mount the loop device and hope to recover some files. When this is queezed out, then maybe a run of e2fsck might recover more valid files ... or ruin the filesystem. Have a nice day :) Thomas
[toc] | [prev] | [next] | [standalone]
| From | "Brian J. Oney" <brian.j.oney@googlemail.com> |
|---|---|
| Date | 2017-11-28 20:40 +0100 |
| Subject | Re: Need Help restoring a filesystem on an external drive WD 'My Book' |
| Message-ID | <uQTTz-7b8-5@gated-at.bofh.it> |
| In reply to | #189375 |
[Multipart message — attachments visible in raw view] — view raw
Hello, the last bit made me laugh. If the situation is truly dire, you may consider file carving with 'scalpel' or 'foremost', both of which are in the repositories. $ apt-cache show foremost scalpel Package: foremost Version: 1.5.7-6 Installed-Size: 123 Maintainer: Raúl Benencia <rul@kalgan.cc> Depends: libc6 (>= 2.14) Description-en: forensic program to recover lost files Foremost is a forensic program to recover lost files based on their headers, footers, and internal data structures. . Foremost can work on image files, such as those generated by dd, Safeback, Encase, etc, or directly on a drive. The headers and footers can be specified by a configuration file or you can use command line switches to specify built-in file types. These built-in types look at the data structures of a given file format allowing for a more reliable and faster recovery. Homepage: http://foremost.sourceforge.net/ Tag: admin::forensics, admin::recovery, hardware::storage, interface::commandline, role::program, scope::utility, security::forensics, use::scanning Filename: pool/main/f/foremost/foremost_1.5.7-6_amd64.deb Package: scalpel Version: 1.60-4 Installed-Size: 82 Maintainer: Debian Forensics <forensics-devel@lists.alioth.debian.org> Depends: libc6 (>= 2.14) Description-en: fast filesystem-independent file recovery scalpel is a fast file carver that reads a database of header and footer definitions and extracts matching files from a set of image files or raw device files. . scalpel is filesystem-independent and will carve files from FAT16, FAT32, exFAT, NTFS, Ext2, Ext3, Ext4, JFS, XFS, ReiserFS, raw partitions, etc. . scalpel is a complete rewrite of the Foremost 0.69 file carver and is useful for both digital forensics investigations and file recovery. Homepage: http://www.digitalforensicssolutions.com/Scalpel Tag: admin::forensics, admin::recovery, role::program, scope::utility, security::forensics Filename: pool/main/s/scalpel/scalpel_1.60-4_amd64.deb Cheers, Brian On Tue, 2017-11-28 at 19:48 +0100, Thomas Schmitt wrote: > Hi, > > arne wrote: > > and I doubt if I understand what is a 'sparse' superblock > > It's not a bad sign, as it seems: > > http://www.nongnu.org/ext2-doc/ext2.html#SUPERBLOCK > "The first version of ext2 (revision 0) stores a copy at the start of > every block group, along with backups of the group descriptor block(s). > Because this can consume a considerable amount of space for large > filesystems, later revisions can optionally reduce the number of backup > copies by only putting backups in specific groups (this is the sparse > superblock feature)." > > > > Command line: TestDisk /log /dev/sdb > > ... > > 1 P partition_map 1 63 63 > > Looks like it recognized a GUID partition table (GPT). > > > 3 P HFS 262208 1953525151 1953262944 > > This would be the ext filesystem's partition. > The following superuser command establishes a read-only loop device which > begins at the given block: > > losetup -o $(expr 262208 '*' 512) -r -f /dev/sdb > > (Contrary to the man page, losetup -f does not tell me the used device path. > I have to run > losetup -l | fgrep /dev/sdb > to learn that it's /dev/loop0.) > > > > Linux 262208 1953525151 1953262944 > > ext2 blocksize=4096 Large file Sparse superblock, 1000 GB / 931 GiB > > recover_EXT2: "e2fsck -b 32768 -B 4096 device" may be needed > > This is probably the normal superblock in that partition. > But running e2fsck might cause the end of the remaining data in the > filesystem. > > I'd try to mount the loop device and hope to recover some files. > When this is queezed out, then maybe a run of e2fsck might recover more > valid files ... or ruin the filesystem. > > > Have a nice day :) > > Thomas >
[toc] | [prev] | [next] | [standalone]
| From | Bernard <bdebreil@teaser.fr> |
|---|---|
| Date | 2017-12-03 19:10 +0100 |
| Subject | Re: Need Help restoring a filesystem on an external drive WD 'My Book' |
| Message-ID | <uSGSe-2wP-21@gated-at.bofh.it> |
| In reply to | #189375 |
Thomas Schmitt wrote: > Hi, > > arne wrote: > > [stuff deleted] > This is probably the normal superblock in that partition. > But running e2fsck might cause the end of the remaining data in the > filesystem. > > I'd try to mount the loop device and hope to recover some files. > When this is queezed out, then maybe a run of e2fsck might recover more > valid files ... or ruin the filesystem. > > > Have a nice day :) > > Thomas > > So, in the mind of trying more of this, I plugged and connected the device once more, for, maybe the thirtieth time... Surprise : this time, it did AUTOMOUNT the way it used to in the old days ! Or, maybe not quite the same way. But it did mount, and I have succeeded in copying files and directories on to another support, which operation took more than 2 hours (it was about 500 Gb). Copy went fine. But I can tell you that, after having shut down and unplugged the device, I could never restart it in a dozen of trials, even in testing other suitable power supplies. This most likely reveals that the hardware is faulty. But it may be interresting to go into details about that exceptional mount. It did automount on /dev/sdb1. But I also could see a /dev/sdb2 in listing /dev.. and, indeed, I was not surprised, since the sdb1 partition was only 500Gb while the device was 1Tb, and that I remembered that I had formated and filled 2 partitions on it. So, I tried to manually mount sdb2, but this wouldn't work : it said : mount : filesystem type 'unknown_LVM2 type' and indeed, what there was supposed to be on this partition, according to the sticker i had left, were large files and directories from my other desktop computer, which is formated in LVM2 (soft RAID filesystem). I don't know what I could have found if I had plugged the device to that Desktop, but I won't have a chance to try. I will inquire to know if I can get that hardware repaired... but I am not too optimistic on this... All of this raises a number of questions concerning safe storage of data. What is available is far from reliable. Another problem is that of usb ports : on two of my three computers, usb ports have become faulty after 2-3 years ; on my old desktop dating back to 2007, on 5 usb ports, 3 are faulty ; when this started, I just had to sligntly move the plug into its slot, but this has ended in the fact that now each trial to plug anything in these slots causes an instant shutdown of the machine. Bernard
[toc] | [prev] | [next] | [standalone]
| From | "Thomas Schmitt" <scdbackup@gmx.net> |
|---|---|
| Date | 2017-12-03 20:10 +0100 |
| Message-ID | <uSHOh-3au-3@gated-at.bofh.it> |
| In reply to | #189519 |
Hi, Bernard wrote: > Surprise : this time, it did AUTOMOUNT the way it used to in the old days ! So there are probably unstable readbility problems with the partition table. If you have the start address of partition 1 then you could try to circumvent the partition table by using a loop device as proposed in https://lists.debian.org/debian-user/2017/11/msg00905.html "losetup -o $(expr 262208 '*' 512) -r -f /dev/sdb" where 262208 was the start address assumed by "TestDisk". > I will inquire to know if I can get that hardware repaired... Given that my local food discounter sells 1 TiB USB3 hard disks for 55 EUR i doubt that it is economically interesting to keep the drive in operation. > All of this raises a number of questions concerning safe storage of data. I am heavily biased towards having multiple backups on optical media. Although they are not overly reliable at backup writing time, once written and verified they survive a long time. > usb ports have become faulty after 2-3 years DVD or BD drives are easier to replace than USB ports, i assume. :)) One could see them as sacrificial hardware for the abrasive effects of environment and time. Normally my drives go blind before the tray servo breaks. Some last since more than 10 years, others died after 20 months. But the SATA or USB sockets where they were plugged had no problems at all. Have a nice day :) Thomas
[toc] | [prev] | [next] | [standalone]
| From | David Wright <deblis@lionunicorn.co.uk> |
|---|---|
| Date | 2017-12-04 02:00 +0100 |
| Subject | Re: Need Help restoring a filesystem on an external drive WD 'My Book' |
| Message-ID | <uSNh1-6kt-9@gated-at.bofh.it> |
| In reply to | #189519 |
On Sun 03 Dec 2017 at 20:10:31 (+0100), Bernard wrote: > All of this raises a number of questions concerning safe storage of > data. What is available is far from reliable. Another problem is > that of usb ports : on two of my three computers, usb ports have > become faulty after 2-3 years ; on my old desktop dating back to > 2007, on 5 usb ports, 3 are faulty ; when this started, I just had > to sligntly move the plug into its slot, but this has ended in the > fact that now each trial to plug anything in these slots causes an > instant shutdown of the machine. For desktops, you can buy USB ports. I have a couple of 3-port ones myself, bought to save the hassle of plugging things into the mobo's ones at the back of the cabinet. They fit where a 3½ floppy would go but there are adapters to fit a 5¼ window as well. Each has two more ports on the card itself. Cheers, David.
[toc] | [prev] | [next] | [standalone]
| From | "Thomas Schmitt" <scdbackup@gmx.net> |
|---|---|
| Date | 2017-11-26 11:50 +0100 |
| Message-ID | <uQ2Fz-6xI-3@gated-at.bofh.it> |
| In reply to | #189295 |
Hi, bd wrote: > My other similar drives mount on /dev/sdb1 or /dev/sr0... Well, sr0 is supposed to be an optical drive: CD, DVD, BD. sdb1 is the first partition on harddisk-like drive sdb: spinning disk, SSD disk, USB stick, ... > If I list my /dev directory using ls -lt, I can see what new device appears > in the list whenever I plug my external drive. It shows 'sdb'. Not 'sdb1' as > for other external drives, just 'sdb'. So it looks like the partition table on the drive is unreadable or was overwritten by data which the Linux kernel interprets as empty partition table or as no partition table. Do you see messages about read errors in the output of dmesg ? ---------------------------------------------------------------------------- Depending on the general readability of the device and/or on the blocks which have been altered, it could be possible to find the filesystem start, mount it by a loop device, or create a new partition table which lets /dev/sd1 mark the area of the filesystem. The main task would be to guess the start of the partition. Its end is of less importance because one could as a make-shift set it to the end of the device. Looking for the signature of ext3, i read in https://superuser.com/questions/239088/whats-a-file-systems-magic-number-in-a-super-block "an ext2/ext3/ext4 filesystem always has the bytes 0x53 0xEF at positions 1080–1081" which is confirmed by http://www.nongnu.org/ext2-doc/ext2.html "The superblock is always located at byte offset 1024 from the beginning of the file, block device or partition formatted with Ext2 and later variants (Ext3, Ext4). [...] Table 3-3. Superblock Structure Offset (bytes) Size (bytes) Description 56 2 s_magic [...] 3.1.16. s_magic 16bit value identifying the file system as Ext2. The value is currently fixed to EXT2_SUPER_MAGIC of value 0xEF53." So one would look for bytes 0x53 0xEF at byte offset 1080 from the start of a full block. Maybe 512-byte-block 63 is a good first guess and block 2048 the next best one. In worst case a little program would have to test a few thousand blocks before finding a candidate for the partition start. As soon as you have a good candidate block address, you may use a loop device on /dev/sdb with byte offset to mount it read-only without the need for writing a new partition table to the drive. (See man 8 losetup, option -o.) In case of mount success you should make a thorough backup of the filesystem content before performing any write operation on the drive. Only with a good backup you should then consider to try repairing the situation. Have a nice day :) Thomas
[toc] | [prev] | [next] | [standalone]
| From | "Alexander V. Makartsev" <avbetev@gmail.com> |
|---|---|
| Date | 2017-11-26 21:10 +0100 |
| Subject | Re: Need Help restoring a filesystem on an external drive WD 'My Book' |
| Message-ID | <uQbpv-42R-3@gated-at.bofh.it> |
| In reply to | #189295 |
[Multipart message — attachments visible in raw view] — view raw
On 26.11.2017 14:37, bd wrote: > > Hi to Everyone, > > My > > WD P/N : WD10000H 1Q > > S/N : WCAU4D 164675 > > is about 4 or 5 years old. It is an external drive using external > power supply. At start, I had formatted it in ext3, so that I 'd be > able to storage videofiles larger than 2 Gb. Since then, I storaged a > number of files in several directories, subdirectories etc.. I never > had any problem until now. > > This drive no longer mounts. It does not mount automatically as it > used to, and I don't know how to mount it manually. My other similar > drives mount on /dev/sdb1 or /dev/sr0... depending on to which > computer I mount it. In case it doesn't automatically mount, I just type : > > #mount /dev/sdb1 /media/bd/ext > > and it works > > but right now I don't know for sure the device name to mount. > > If I list my /dev directory using ls -lt, I can see what new device > appears in the list whenever I plug my external drive. It shows 'sdb'. > Not 'sdb1' as for other external drives, just 'sdb'. If now I type : > > # mount /dev/sdb /media/bd/ext > > this gets the external drive to react : the light goes up and down for > awhile, and then I get this message : > > 'you must specify the filesystem' > > But, if I try : > > # mount -t ext3 /dev/sdb /media/bd/ext > > I get this : 'wrong fs type, bad option, bad superblock on /dev/sdb…' > > same result if I try mounting on 'fat', 'msdos'… filesystems, but I > doubt if there are any FAT or msdos space left on this device since I > had reformated it to ext3. > > At last, I tried : > > # fsck /dev/sdb (the external drive starts to light, then : > > 'fsck ext2 : superblock invalid. Trying to backup blocks > > fsck ext2 : bad magic number in superblock while trying to open /dev/sdb > > Now, if I type : > > cat /proc/scsi/scsi > > I get this : > > scsi0 ATA MAXTOR STM > > scsi1 ATA MAXTOR STM > > scsi5 WD My Book Direct Access > > > /etc/fstab > > does not show any sdb device > > How am I to get this drive back to operation, or, at least, to > recuperate the datafiles that are stored in that WD external drive ? > > Thanks in advance to tell me what diagnosis and repair tools I could use > > Bernard > You have to specify partition to mount not whole disk device. First of all check if you got disk name right (they could mix up on boot time): # blkid After that, right mount command should be like this: # mount -t ext3 /dev/sdb1 /media/bd/ext If you suspect disk could be failing, you can mount it as read-only, to see if it will mount cleanly: # mount -t ext3 -o ro /dev/sdb1 /media/bd/ext To check unmounted ext3 filesystem of partition 1 you should type: # fsck.ext3 /dev/sdb1 -- With kindest regards, Alexander. ⢀⣴⠾⠻⢶⣦⠀ ⣾⠁⢠⠒⠀⣿⡁ Debian - The universal operating system ⢿⡄⠘⠷⠚⠋⠀ https://www.debian.org ⠈⠳⣄⠀⠀⠀⠀
[toc] | [prev] | [next] | [standalone]
| From | David Christensen <dpchrist@holgerdanske.com> |
|---|---|
| Date | 2017-11-26 22:40 +0100 |
| Subject | Re: Need Help restoring a filesystem on an external drive WD 'My Book' |
| Message-ID | <uQcOB-4PK-9@gated-at.bofh.it> |
| In reply to | #189295 |
On 11/26/17 01:37, bd wrote:
> WD P/N : WD10000H 1Q
>
> S/N : WCAU4D 164675
>
> is about 4 or 5 years old. It is an external drive using external power
> supply. At start, I had formatted it in ext3, so that I 'd be able to
> storage videofiles larger than 2 Gb. Since then, I storaged a number of
> files in several directories, subdirectories etc.. I never had any
> problem until now.
>
> This drive no longer mounts.
Were there any events immediately prior to this change -- power outage,
dropped the external drive, updated software, installed software,
changed system configuration settings, etc.?
> It does not mount automatically as it used
> to, and I don't know how to mount it manually. My other similar drives
> mount on /dev/sdb1 or /dev/sr0... depending on to which computer I mount
> it. In case it doesn't automatically mount, I just type :
>
> #mount /dev/sdb1 /media/bd/ext
>
> and it works
That incantation might work, if the external drive is assigned to
/dev/sdb by the kernel, the HDD has a partition table, the ext3 file
system is in the first partition, and the directory /media/bd/ext
exists. But, the /media directory is usually managed by automount
software, so messing with it could cause problems. I typically put my
mount points under /mnt.
> but right now I don't know for sure the device name to mount.
>
> If I list my /dev directory using ls -lt, I can see what new device
> appears in the list whenever I plug my external drive. It shows 'sdb'.
> Not 'sdb1' as for other external drives, just 'sdb'. If now I type :
>
> # mount /dev/sdb /media/bd/ext
That would be correct only if you put the ext3 file system directly on
the raw drive without a partition table. As you stated it used to mount
automatically, that implies a partition table. Therefore, this
incantation is likely wrong.
> this gets the external drive to react : the light goes up and down for
> awhile, and then I get this message :
>
> 'you must specify the filesystem'
>
> But, if I try :
>
> # mount -t ext3 /dev/sdb /media/bd/ext
>
> I get this : 'wrong fs type, bad option, bad superblock on /dev/sdb…'
Also, likely a wrong incantation.
> same result if I try mounting on 'fat', 'msdos'… filesystems, but I
> doubt if there are any FAT or msdos space left on this device since I
> had reformated it to ext3.
>
> At last, I tried :
>
> # fsck /dev/sdb (the external drive starts to light, then :
>
> 'fsck ext2 : superblock invalid. Trying to backup blocks
>
> fsck ext2 : bad magic number in superblock while trying to open /dev/sdb
Also, likely a wrong incantation; and dangerous. Hopefully, fsck(8)
didn't overwrite any bits on disk.
> Now, if I type :
>
> cat /proc/scsi/scsi
>
> I get this :
>
> scsi0 ATA MAXTOR STM
>
> scsi1 ATA MAXTOR STM
>
> scsi5 WD My Book Direct Access
So, the kernel can see the drive at least part of the time.
> /etc/fstab
>
> does not show any sdb device
/etc/fstab typically contains entries created by the installer and by
the system administrator (you). Automatic mounting should not modify
this file.
> How am I to get this drive back to operation, or, at least, to
> recuperate the datafiles that are stored in that WD external drive ?
>
> Thanks in advance to tell me what diagnosis and repair tools I could use
All the software in the world won't help you if the hardware is failing
-- the external power supply could be bad, the electronics in the
plastic box could be bad, or the drive could be bad. I've seen all three.
Download and run WD's Data Lifeguard Diagnostic to verify the external
drive:
https://support.wdc.com/downloads.aspx
Reply with the results.
David
[toc] | [prev] | [next] | [standalone]
| From | Richard Hector <richard@walnut.gen.nz> |
|---|---|
| Date | 2017-11-27 03:10 +0100 |
| Subject | Re: Need Help restoring a filesystem on an external drive WD 'My Book' |
| Message-ID | <uQh1U-7Bb-3@gated-at.bofh.it> |
| In reply to | #189295 |
[Multipart message — attachments visible in raw view] — view raw
On 26/11/17 22:37, bd wrote: > This drive no longer mounts FWIW, my WD external drive stopped mounting. I opened the case (with difficulty, and possibly breakage, IIRC) removed the drive, and used it as a normal SATA drive. Still working fine, all the data was there. This may be completely unrelated to your issue ... Richard
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.user
csiph-web