Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #189295 > unrolled thread

Need Help restoring a filesystem on an external drive WD 'My Book'

Started bybd <bdebreil@teaser.fr>
First post2017-11-26 11:10 +0100
Last post2017-11-27 03:10 +0100
Articles 12 — 9 participants

Back to article view | Back to linux.debian.user


Contents

  Need Help restoring a filesystem on an external drive WD 'My Book' bd <bdebreil@teaser.fr> - 2017-11-26 11:10 +0100
    Re: Need Help restoring a filesystem on an external drive WD 'My  Book' arne <sp113438@telfort.nl> - 2017-11-26 11:20 +0100
      Re: Need Help restoring a filesystem on an external drive WD 'My  Book' Bernard <bdebreil@teaser.fr> - 2017-11-28 17:20 +0100
        Re: Need Help restoring a filesystem on an external drive WD 'My Book' "Thomas Schmitt" <scdbackup@gmx.net> - 2017-11-28 19:50 +0100
          Re: Need Help restoring a filesystem on an external drive WD 'My  Book' "Brian J. Oney" <brian.j.oney@googlemail.com> - 2017-11-28 20:40 +0100
          Re: Need Help restoring a filesystem on an external drive WD 'My  Book' Bernard <bdebreil@teaser.fr> - 2017-12-03 19:10 +0100
            Re: Need Help restoring a filesystem on an external drive WD 'My Book' "Thomas Schmitt" <scdbackup@gmx.net> - 2017-12-03 20:10 +0100
            Re: Need Help restoring a filesystem on an external drive WD 'My  Book' David Wright <deblis@lionunicorn.co.uk> - 2017-12-04 02:00 +0100
    Re: Need Help restoring a filesystem on an external drive WD 'My Book' "Thomas Schmitt" <scdbackup@gmx.net> - 2017-11-26 11:50 +0100
    Re: Need Help restoring a filesystem on an external drive WD 'My  Book' "Alexander V. Makartsev" <avbetev@gmail.com> - 2017-11-26 21:10 +0100
    Re: Need Help restoring a filesystem on an external drive WD 'My  Book' David Christensen <dpchrist@holgerdanske.com> - 2017-11-26 22:40 +0100
    Re: Need Help restoring a filesystem on an external drive WD 'My  Book' Richard Hector <richard@walnut.gen.nz> - 2017-11-27 03:10 +0100

#189295 — Need Help restoring a filesystem on an external drive WD 'My Book'

Frombd <bdebreil@teaser.fr>
Date2017-11-26 11:10 +0100
SubjectNeed Help restoring a filesystem on an external drive WD 'My Book'
Message-ID<uQ22S-6jt-1@gated-at.bofh.it>

[Multipart message — attachments visible in raw view] — view raw

Hi to Everyone,

My

WD P/N : WD10000H 1Q

S/N : WCAU4D 164675

is about 4 or 5 years old. It is an external drive using external power 
supply. At start, I had formatted it in ext3, so that I 'd be able to 
storage videofiles larger than 2 Gb. Since then, I storaged a number of 
files in several directories, subdirectories etc.. I never had any 
problem until now.

This drive no longer mounts. It does not mount automatically as it used 
to, and I don't know how to mount it manually. My other similar drives 
mount on /dev/sdb1 or /dev/sr0... depending on to which computer I mount 
it. In case it doesn't automatically mount, I just type :

#mount /dev/sdb1 /media/bd/ext

and it works

but right now I don't know for sure the device name to mount.

If I list my /dev directory using ls -lt, I can see what new device 
appears in the list whenever I plug my external drive. It shows 'sdb'. 
Not 'sdb1' as for other external drives, just 'sdb'. If now I type :

# mount /dev/sdb /media/bd/ext

this gets the external drive to react : the light goes up and down for 
awhile, and then I get this message :

'you must specify the filesystem'

But, if I try :

# mount -t ext3 /dev/sdb /media/bd/ext

I get this : 'wrong fs type, bad option, bad superblock on /dev/sdb…'

same result if I try mounting on 'fat', 'msdos'… filesystems, but I 
doubt if there are any FAT or msdos space left on this device since I 
had reformated it to ext3.

At last, I tried :

# fsck /dev/sdb (the external drive starts to light, then :

'fsck ext2 : superblock invalid. Trying to backup blocks

fsck ext2 : bad magic number in superblock while trying to open /dev/sdb

Now, if I type :

cat /proc/scsi/scsi

I get this :

scsi0 ATA MAXTOR STM

scsi1 ATA MAXTOR STM

scsi5 WD My Book Direct Access


/etc/fstab

does not show any sdb device

How am I to get this drive back to operation, or, at least, to 
recuperate the datafiles that are stored in that WD external drive ?

Thanks in advance to tell me what diagnosis and repair tools I could use

Bernard

[toc] | [next] | [standalone]


#189296 — Re: Need Help restoring a filesystem on an external drive WD 'My Book'

Fromarne <sp113438@telfort.nl>
Date2017-11-26 11:20 +0100
SubjectRe: Need Help restoring a filesystem on an external drive WD 'My Book'
Message-ID<uQ2cx-6n0-1@gated-at.bofh.it>
In reply to#189295
> How am I to get this drive back to operation, or, at least, to 
> recuperate the datafiles that are stored in that WD external drive ?
> 
> Thanks in advance to tell me what diagnosis and repair tools I could
> use
> 
> Bernard

Hello,

TestDisk checks the partition and boot sectors of your disks.
 It is very useful in forensics, recovering lost partitions.

PhotoRec is file data recovery software designed to recover lost
pictures from digital camera memory or even Hard Disks.It has been
extended to search also for non audio/video headers.

Both are in the packet testdisk

Hope this helps,

Greeting.

[toc] | [prev] | [next] | [standalone]


#189370 — Re: Need Help restoring a filesystem on an external drive WD 'My Book'

FromBernard <bdebreil@teaser.fr>
Date2017-11-28 17:20 +0100
SubjectRe: Need Help restoring a filesystem on an external drive WD 'My Book'
Message-ID<uQQM1-5lk-1@gated-at.bofh.it>
In reply to#189296
Thanks to All for your advises. Indeed, I most likely have a hardware 
problem with this WD external drive. It no longer boots, that is for 
sure... But, at most starts it get registered as scsi drive, as reveals

$cat /proc/scsi/scsi

it does most times, not all times. When it does not, I have to unplug 
an,d replug it, and it will likely registers. Once registered, it 
remains so.

Anyway, for a start I tried 'TestDisk. the test lasted about five hours, 
and I copy/paste the log file below. In this text, I pointed out 16 
lines that suggest a call to 'e2fsck', each with different paramaters 
for -b and -B. Prior to try this, I thought I'd better ask your advices 
first.

"e2fsck -b 214990848 -B 4096 device" may be needed

.....

I also noticed such lines :

ext2 blocksize=4096 Large file Sparse superblock, 1000 GB / 931 GiB

and I doubt if I understand what is a 'sparse' superblock

Also, about what the logfile mentions on FAT partitions... I don't think I had a fat partition left ever since I had, about 4-5 years ago,reformatted the whole drive to ext2. But there maybe remains of erased FAT partition, as I can't remember whether the reformat that I did was a deep reformat or not.

Now, here is the logfile as its whole :
 

Using locale 'fr_FR.UTF-8'.
Terminal has only 22 lines
Using locale 'fr_FR.UTF-8'.
Terminal has only 22 lines
Using locale 'fr_FR.UTF-8'.


Mon Nov 27 16:20:47 2017
Command line: TestDisk /log /dev/sdb

TestDisk 6.14, Data Recovery Utility, July 2013
Christophe GRENIER <grenier@cgsecurity.org>
http://www.cgsecurity.org
OS: Linux, kernel 3.13.0-32-generic (#57-Ubuntu SMP Tue Jul 15 03:51:08 UTC 2014) x86_64
Compiler: GCC 4.8
Compilation date: 2013-10-29T01:29:29
ext2fs lib: 1.42.9, ntfs lib: libntfs-3g, reiserfs lib: none, ewf lib: none
Hard disk list
Disk /dev/sdb - 1000 GB / 931 GiB - CHS 121601 255 63, sector size=512 - WD My Book, FW:1028

Partition table type (auto): Mac
Disk /dev/sdb - 1000 GB / 931 GiB - WD My Book
Partition table type: Mac

Analyse Disk /dev/sdb - 1000 GB / 931 GiB - CHS 121601 255 63
check_part_mac failed for partition type AF
Current partition structure:
 1 P partition_map                  1         63         63
 2 P Free                          64     262207     262144
 3 P HFS                       262208 1953525151 1953262944
 3 P HFS                       262208 1953525151 1953262944
 4 P Free                  1953525152 1953525167         16

search_part()
Disk /dev/sdb - 1000 GB / 931 GiB - CHS 121601 255 63
     Linux                     262208 1953525151 1953262944
     ext2 blocksize=4096 Large file Sparse superblock, 1000 GB / 931 GiB

interface_write()
   P Linux                     262208 1953525151 1953262944

search_part()
Disk /dev/sdb - 1000 GB / 931 GiB - CHS 121601 255 63
     Linux                     262208 1953525151 1953262944
     ext2 blocksize=4096 Large file Sparse superblock, 1000 GB / 931 GiB
recover_EXT2: "e2fsck -b 32768 -B 4096 device" may be needed
     Linux                     262208 1953525151 1953262944
     ext2 blocksize=4096 Large file Sparse superblock Backup superblock, 1000 GB / 931 GiB
recover_EXT2: "e2fsck -b 98304 -B 4096 device" may be needed
     Linux                     262208 1953525151 1953262944
     ext2 blocksize=4096 Large file Sparse superblock Backup superblock, 1000 GB / 931 GiB
recover_EXT2: "e2fsck -b 163840 -B 4096 device" may be needed
     Linux                     262208 1953525151 1953262944
     ext2 blocksize=4096 Large file Sparse superblock Backup superblock, 1000 GB / 931 GiB
recover_EXT2: "e2fsck -b 229376 -B 4096 device" may be needed
     Linux                     262208 1953525151 1953262944
     ext2 blocksize=4096 Large file Sparse superblock Backup superblock, 1000 GB / 931 GiB
recover_EXT2: "e2fsck -b 294912 -B 4096 device" may be needed
     Linux                     262208 1953525151 1953262944
     ext2 blocksize=4096 Large file Sparse superblock Backup superblock, 1000 GB / 931 GiB
recover_EXT2: "e2fsck -b 819200 -B 4096 device" may be needed
     Linux                     262208 1953525151 1953262944
     ext2 blocksize=4096 Large file Sparse superblock Backup superblock, 1000 GB / 931 GiB
recover_EXT2: "e2fsck -b 884736 -B 4096 device" may be needed
     Linux                     262208 1953525151 1953262944
     ext2 blocksize=4096 Large file Sparse superblock Backup superblock, 1000 GB / 931 GiB
recover_EXT2: "e2fsck -b 1605632 -B 4096 device" may be needed
     Linux                     262208 1953525151 1953262944
     ext2 blocksize=4096 Large file Sparse superblock Backup superblock, 1000 GB / 931 GiB
recover_EXT2: "e2fsck -b 2654208 -B 4096 device" may be needed
     Linux                     262208 1953525151 1953262944
     ext2 blocksize=4096 Large file Sparse superblock Backup superblock, 1000 GB / 931 GiB
recover_EXT2: "e2fsck -b 4096000 -B 4096 device" may be needed
     Linux                     262208 1953525151 1953262944
     ext2 blocksize=4096 Large file Sparse superblock Backup superblock, 1000 GB / 931 GiB
recover_EXT2: "e2fsck -b 7962624 -B 4096 device" may be needed
     Linux                     262208 1953525151 1953262944
     ext2 blocksize=4096 Large file Sparse superblock Backup superblock, 1000 GB / 931 GiB
recover_EXT2: "e2fsck -b 11239424 -B 4096 device" may be needed
     Linux                     262208 1953525151 1953262944
     ext2 blocksize=4096 Large file Sparse superblock Backup superblock, 1000 GB / 931 GiB
recover_EXT2: "e2fsck -b 20480000 -B 4096 device" may be needed
     Linux                     262208 1953525151 1953262944
     ext2 blocksize=4096 Large file Sparse superblock Backup superblock, 1000 GB / 931 GiB
recover_EXT2: "e2fsck -b 23887872 -B 4096 device" may be needed
     Linux                     262208 1953525151 1953262944
     ext2 blocksize=4096 Large file Sparse superblock Backup superblock, 1000 GB / 931 GiB
recover_EXT2: "e2fsck -b 71663616 -B 4096 device" may be needed
     Linux                     262208 1953525151 1953262944
     ext2 blocksize=4096 Large file Sparse superblock Backup superblock, 1000 GB / 931 GiB
recover_EXT2: "e2fsck -b 78675968 -B 4096 device" may be needed
     Linux                     262208 1953525151 1953262944
     ext2 blocksize=4096 Large file Sparse superblock Backup superblock, 1000 GB / 931 GiB
recover_EXT2: "e2fsck -b 102400000 -B 4096 device" may be needed
     Linux                     262208 1953525151 1953262944
     ext2 blocksize=4096 Large file Sparse superblock Backup superblock, 1000 GB / 931 GiB
FAT differs, FAT sectors=0-8/8
heads/cylinder 4 (FAT) != 255 (HD)
sect/track 17 (FAT) != 63 (HD)
     Unknown               1232803376 1232824114      20739 [NO NAME]
     FAT12, blocksize=4096, 10 MB / 10 MiB
check_FAT: Unusual media descriptor (0xf0!=0xf8)
heads/cylinder 2 (FAT) != 255 (HD)
sect/track 18 (FAT) != 63 (HD)
     Unknown               1248094824 1248097703       2880 [Debian Inst]
     FAT12, blocksize=512, 1474 KB / 1440 KiB
     Linux                 1248097704 1248100583       2880
     ext2 blocksize=1024, 1474 KB / 1440 KiB
check_FAT: Unusual media descriptor (0xf0!=0xf8)
heads/cylinder 2 (FAT) != 255 (HD)
sect/track 18 (FAT) != 63 (HD)
     Unknown               1248100584 1248103463       2880 [Debian Inst]
     FAT12, blocksize=512, 1474 KB / 1440 KiB
check_FAT: Unusual media descriptor (0xf0!=0xf8)
heads/cylinder 2 (FAT) != 255 (HD)
sect/track 36 (FAT) != 63 (HD)
     Unknown               1567964760 1567970519       5760 [Debian Inst]
     FAT12, blocksize=1024, 2949 KB / 2880 KiB
check_FAT: Unusual media descriptor (0xf0!=0xf8)
heads/cylinder 2 (FAT) != 255 (HD)
sect/track 36 (FAT) != 63 (HD)
     Unknown               1695513088 1695518847       5760 [Debian Inst]
     FAT12, blocksize=1024, 2949 KB / 2880 KiB
FAT differs, FAT sectors=0-8/8
heads/cylinder 4 (FAT) != 255 (HD)
sect/track 17 (FAT) != 63 (HD)
     Unknown               1698249656 1698270394      20739 [NO NAME]
     FAT12, blocksize=4096, 10 MB / 10 MiB
check_FAT: Unusual media descriptor (0xf0!=0xf8)
heads/cylinder 2 (FAT) != 255 (HD)
sect/track 18 (FAT) != 63 (HD)
     Unknown               1714882408 1714885287       2880 [Debian Inst]
     FAT12, blocksize=512, 1474 KB / 1440 KiB
     Linux                 1714885288 1714888167       2880
     ext2 blocksize=1024, 1474 KB / 1440 KiB
check_FAT: Unusual media descriptor (0xf0!=0xf8)
heads/cylinder 2 (FAT) != 255 (HD)
sect/track 18 (FAT) != 63 (HD)
     Unknown               1714888168 1714891047       2880 [Debian Inst]
     FAT12, blocksize=512, 1474 KB / 1440 KiB
recover_EXT2: "e2fsck -b 214990848 -B 4096 device" may be needed
     Linux                     262208 1953525151 1953262944
     ext2 blocksize=4096 Large file Sparse superblock Backup superblock, 1000 GB / 931 GiB

interface_write()
 
No partition found or selected for recovery
simulate write!

Interface Advanced
check_part_mac failed for partition type AF
 1 P partition_map                  1         63         63
 2 P Free                          64     262207     262144
 3 P HFS                       262208 1953525151 1953262944
 4 P Free                  1953525152 1953525167         16

HFS_HFSP_boot_sector
 3 P HFS                       262208 1953525151 1953262944
Volume header
Bad

Backup volume header
Bad

Sectors are not identical.

HFS_HFSP_boot_sector
 3 P HFS                       262208 1953525151 1953262944
Volume header
Bad

Backup volume header
Bad

Sectors are not identical.
Superblock                        Backup superblock
0000 0080a303 ac8d8d0e   ........  00000000 00000000   ........
0008 1547ba00 bcd4e602   .G......  00000000 00000000   ........
0010 7471a103 00000000   tq......  00000000 00000000   ........
0018 02000000 02000000   ........  00000000 00000000   ........
0020 00800000 00800000   ........  00000000 00000000   ........
0028 00200000 9de01159   . .....Y  00000000 00000000   ........
0030 00e21159 56002400   ...YV.$.  00000000 00000000   ........
0038 53ef0000 01000000   S.......  00000000 00000000   ........
0040 0388dd4b 004eed00   ...K.N..  00000000 00000000   ........
0048 00000000 01000000   ........  00000000 00000000   ........
0050 00000000 0b000000   ........  00000000 00000000   ........
0058 00010000 38000000   ....8...  00000000 00000000   ........
0060 02000000 03000000   ........  00000000 00000000   ........
0068 6f048c19 5ed54af8   o...^.J.  00000000 00000000   ........
0070 b665401f 92a05116   .e@...Q.  00000000 00000000   ........
0078 00000000 00000000   ........  00000000 00000000   ........
0080 00000000 00000000   ........  00000000 00000000   ........
0088 2f6d6564 69612f62   /media/b  00000000 00000000   ........
0090 642f3666 30343863   d/6f048c  00000000 00000000   ........
0098 31392d35 6564352d   19-5ed5-  00000000 00000000   ........
00A0 34616638 2d623636   4af8-b66  00000000 00000000   ........
00A8 352d3430 31663932   5-401f92  00000000 00000000   ........
00B0 61303531 31360000   a05116..  00000000 00000000   ........
00B8 00000000 00000000   ........  00000000 00000000   ........
00C0 00000000 00000000   ........  00000000 00000000   ........
00C8 00000000 0000c503   ........  00000000 00000000   ........
00D0 00000000 00000000   ........  00000000 00000000   ........
00D8 00000000 00000000   ........  00000000 00000000   ........
00E0 00000000 00000000   ........  00000000 00000000   ........
00E8 00000000 214ef652   ....!N.R  00000000 00000000   ........
00F0 54f54df2 a8d486b3   T.M.....  00000000 00000000   ........
00F8 0bc68920 01000000   ... ....  00000000 00000000   ........
0100 00000000 00000000   ........  00000000 00000000   ........
0108 0388dd4b 00000000   ...K....  00000000 00000000   ........
0110 00000000 00000000   ........  00000000 00000000   ........
0118 00000000 00000000   ........  00000000 00000000   ........
0120 00000000 00000000   ........  00000000 00000000   ........
0128 00000000 00000000   ........  00000000 00000000   ........
0130 00000000 00000000   ........  00000000 00000000   ........
0138 00000000 00000000   ........  00000000 00000000   ........
0140 00000000 00000000   ........  00000000 00000000   ........
0148 00000000 00000000   ........  00000000 00000000   ........
0150 00000000 00000000   ........  00000000 00000000   ........
0158 00000000 1c001c00   ........  00000000 00000000   ........
0160 01000000 00000000   ........  00000000 00000000   ........
0168 00000000 00000000   ........  00000000 00000000   ........
0170 00000000 00000000   ........  00000000 00000000   ........
0178 b0c11301 00000000   ........  00000000 00000000   ........
0180 00000000 00000000   ........  00000000 00000000   ........
0188 00000000 00000000   ........  00000000 00000000   ........
0190 00000000 00000000   ........  00000000 00000000   ........
0198 00000000 00000000   ........  00000000 00000000   ........
01A0 00000000 00000000   ........  00000000 00000000   ........
01A8 00000000 00000000   ........  00000000 00000000   ........
01B0 00000000 00000000   ........  00000000 00000000   ........
01B8 00000000 00000000   ........  00000000 00000000   ........
01C0 00000000 00000000   ........  00000000 00000000   ........
01C8 00000000 00000000   ........  00000000 00000000   ........
01D0 00000000 00000000   ........  00000000 00000000   ........
01D8 00000000 00000000   ........  00000000 00000000   ........
01E0 00000000 00000000   ........  00000000 00000000   ........
01E8 00000000 00000000   ........  00000000 00000000   ........
01F0 00000000 00000000   ........  00000000 00000000   ........
01F8 00000000 00000000   ........  00000000 00000000   ........

Interface Advanced
check_part_mac failed for partition type AF
 1 P partition_map                  1         63         63
 2 P Free                          64     262207     262144
 3 P HFS                       262208 1953525151 1953262944
 4 P Free                  1953525152 1953525167         16

TestDisk exited normally.




arne wrote:
>> How am I to get this drive back to operation, or, at least, to 
>> recuperate the datafiles that are stored in that WD external drive ?
>>
>> Thanks in advance to tell me what diagnosis and repair tools I could
>> use
>>
>> Bernard
>>     
>
> Hello,
>
> TestDisk checks the partition and boot sectors of your disks.
>  It is very useful in forensics, recovering lost partitions.
>
> PhotoRec is file data recovery software designed to recover lost
> pictures from digital camera memory or even Hard Disks.It has been
> extended to search also for non audio/video headers.
>
> Both are in the packet testdisk
>
> Hope this helps,
>
> Greeting.
>
>
>
>   

[toc] | [prev] | [next] | [standalone]


#189375

From"Thomas Schmitt" <scdbackup@gmx.net>
Date2017-11-28 19:50 +0100
Message-ID<uQT7b-6Ge-1@gated-at.bofh.it>
In reply to#189370
Hi,

arne wrote:
> and I doubt if I understand what is a 'sparse' superblock

It's not a bad sign, as it seems:

  http://www.nongnu.org/ext2-doc/ext2.html#SUPERBLOCK
  "The first version of ext2 (revision 0) stores a copy at the start of
   every block group, along with backups of the group descriptor block(s).
   Because this can consume a considerable amount of space for large
   filesystems, later revisions can optionally reduce the number of backup
   copies by only putting backups in specific groups (this is the sparse
   superblock feature)."


> Command line: TestDisk /log /dev/sdb
> ...
> 1 P partition_map                  1         63         63

Looks like it recognized a GUID partition table (GPT).

> 3 P HFS                       262208 1953525151 1953262944

This would be the ext filesystem's partition.
The following superuser command establishes a read-only loop device which
begins at the given block:

  losetup -o $(expr 262208 '*' 512) -r -f /dev/sdb

(Contrary to the man page, losetup -f does not tell me the used device path.
 I have to run
   losetup -l | fgrep /dev/sdb
 to learn that it's /dev/loop0.)


>     Linux                     262208 1953525151 1953262944
>     ext2 blocksize=4096 Large file Sparse superblock, 1000 GB / 931 GiB
> recover_EXT2: "e2fsck -b 32768 -B 4096 device" may be needed

This is probably the normal superblock in that partition.
But running e2fsck might cause the end of the remaining data in the
filesystem.

I'd try to mount the loop device and hope to recover some files.
When this is queezed out, then maybe a run of e2fsck might recover more
valid files ... or ruin the filesystem.


Have a nice day :)

Thomas

[toc] | [prev] | [next] | [standalone]


#189377 — Re: Need Help restoring a filesystem on an external drive WD 'My Book'

From"Brian J. Oney" <brian.j.oney@googlemail.com>
Date2017-11-28 20:40 +0100
SubjectRe: Need Help restoring a filesystem on an external drive WD 'My Book'
Message-ID<uQTTz-7b8-5@gated-at.bofh.it>
In reply to#189375

[Multipart message — attachments visible in raw view] — view raw

Hello,
the last bit made me laugh. If the situation is truly dire, you may consider file carving with 'scalpel' or 'foremost', both of which are in the repositories.

$ apt-cache show foremost scalpel
Package: foremost
Version: 1.5.7-6
Installed-Size: 123
Maintainer: Raúl Benencia <rul@kalgan.cc>
Depends: libc6 (>= 2.14)
Description-en: forensic program to recover lost files
 Foremost is a forensic program to recover lost files based on
 their headers, footers, and internal data structures.
 .
 Foremost can work on image files, such as those generated by dd,
 Safeback, Encase, etc, or directly on a drive. The headers and
 footers can be specified by a configuration file or you can use
 command line switches to specify built-in file types. These built-in
 types look at the data structures of a given file format allowing
 for a more reliable and faster recovery.
Homepage: http://foremost.sourceforge.net/
Tag: admin::forensics, admin::recovery, hardware::storage,
 interface::commandline, role::program, scope::utility,
 security::forensics, use::scanning
Filename: pool/main/f/foremost/foremost_1.5.7-6_amd64.deb

Package: scalpel
Version: 1.60-4
Installed-Size: 82
Maintainer: Debian Forensics <forensics-devel@lists.alioth.debian.org>
Depends: libc6 (>= 2.14)
Description-en: fast filesystem-independent file recovery
 scalpel is a fast file carver that reads a database of header and footer
 definitions and extracts matching files from a set of image files or raw
 device files.
 .
 scalpel is filesystem-independent and will carve files from FAT16, FAT32,
 exFAT, NTFS, Ext2, Ext3, Ext4, JFS, XFS, ReiserFS, raw partitions, etc.
 .
 scalpel is a complete rewrite of the Foremost 0.69 file carver and is
 useful for both digital forensics investigations and file recovery.
Homepage: http://www.digitalforensicssolutions.com/Scalpel
Tag: admin::forensics, admin::recovery, role::program, scope::utility,
 security::forensics
Filename: pool/main/s/scalpel/scalpel_1.60-4_amd64.deb

Cheers,
Brian


On Tue, 2017-11-28 at 19:48 +0100, Thomas Schmitt wrote:
> Hi,
> 
> arne wrote:
> > and I doubt if I understand what is a 'sparse' superblock
> 
> It's not a bad sign, as it seems:
> 
>   http://www.nongnu.org/ext2-doc/ext2.html#SUPERBLOCK
>   "The first version of ext2 (revision 0) stores a copy at the start of
>    every block group, along with backups of the group descriptor block(s).
>    Because this can consume a considerable amount of space for large
>    filesystems, later revisions can optionally reduce the number of backup
>    copies by only putting backups in specific groups (this is the sparse
>    superblock feature)."
> 
> 
> > Command line: TestDisk /log /dev/sdb
> > ...
> > 1 P partition_map                  1         63         63
> 
> Looks like it recognized a GUID partition table (GPT).
> 
> > 3 P HFS                       262208 1953525151 1953262944
> 
> This would be the ext filesystem's partition.
> The following superuser command establishes a read-only loop device which
> begins at the given block:
> 
>   losetup -o $(expr 262208 '*' 512) -r -f /dev/sdb
> 
> (Contrary to the man page, losetup -f does not tell me the used device path.
>  I have to run
>    losetup -l | fgrep /dev/sdb
>  to learn that it's /dev/loop0.)
> 
> 
> >     Linux                     262208 1953525151 1953262944
> >     ext2 blocksize=4096 Large file Sparse superblock, 1000 GB / 931 GiB
> > recover_EXT2: "e2fsck -b 32768 -B 4096 device" may be needed
> 
> This is probably the normal superblock in that partition.
> But running e2fsck might cause the end of the remaining data in the
> filesystem.
> 
> I'd try to mount the loop device and hope to recover some files.
> When this is queezed out, then maybe a run of e2fsck might recover more
> valid files ... or ruin the filesystem.
> 
> 
> Have a nice day :)
> 
> Thomas
> 

[toc] | [prev] | [next] | [standalone]


#189519 — Re: Need Help restoring a filesystem on an external drive WD 'My Book'

FromBernard <bdebreil@teaser.fr>
Date2017-12-03 19:10 +0100
SubjectRe: Need Help restoring a filesystem on an external drive WD 'My Book'
Message-ID<uSGSe-2wP-21@gated-at.bofh.it>
In reply to#189375
Thomas Schmitt wrote:
> Hi,
>
> arne wrote:
>   
> [stuff deleted]
> This is probably the normal superblock in that partition.
> But running e2fsck might cause the end of the remaining data in the
> filesystem.
>
> I'd try to mount the loop device and hope to recover some files.
> When this is queezed out, then maybe a run of e2fsck might recover more
> valid files ... or ruin the filesystem.
>
>
> Have a nice day :)
>
> Thomas
>
>   
So, in the mind of trying more of this, I plugged and connected the 
device once more, for, maybe the thirtieth time... Surprise : this time, 
it did AUTOMOUNT the way it used to in the old days ! Or, maybe not 
quite the same way.  But it did mount, and I have succeeded in copying 
files and directories on to another support, which operation took more 
than 2 hours (it was about 500 Gb). Copy went fine. But I can tell you 
that, after having shut down and unplugged the device, I could never 
restart it in a dozen of trials, even in testing other suitable power 
supplies. This most likely reveals that the hardware is faulty.

But it may be interresting to go into details about that exceptional 
mount. It did automount on /dev/sdb1. But I also could see a /dev/sdb2 
in listing /dev.. and, indeed, I was not surprised, since the sdb1 
partition was only 500Gb while the device was 1Tb, and that I remembered 
that I had formated and filled 2 partitions on it. So, I tried to 
manually mount sdb2, but this wouldn't work : it said :

mount : filesystem type 'unknown_LVM2 type'

and indeed, what there was supposed to be on this partition, according 
to the sticker i had left, were large files and directories from my 
other desktop computer, which is formated in LVM2 (soft RAID 
filesystem). I don't know what I could have found if I had plugged the 
device to that Desktop, but I won't have a chance to try.

I will inquire to know if I can get that hardware repaired... but I am 
not too optimistic on this...

All of this raises a number of questions concerning safe storage of 
data. What is available is far from reliable. Another problem is that of 
usb ports : on two of my three computers, usb ports have become faulty 
after 2-3 years ; on my old desktop dating back to 2007, on 5 usb ports, 
3 are faulty ; when this started, I just had to sligntly move the plug 
into its slot, but this has ended in the fact that now each trial to 
plug anything in these slots causes an instant shutdown of the machine.

Bernard

[toc] | [prev] | [next] | [standalone]


#189521

From"Thomas Schmitt" <scdbackup@gmx.net>
Date2017-12-03 20:10 +0100
Message-ID<uSHOh-3au-3@gated-at.bofh.it>
In reply to#189519
Hi,

Bernard wrote:
> Surprise : this time, it did AUTOMOUNT the way it used to in the old days !

So there are probably unstable readbility problems with the partition table.

If you have the start address of partition 1 then you could try to
circumvent the partition table by using a loop device as proposed in
  https://lists.debian.org/debian-user/2017/11/msg00905.html
  "losetup -o $(expr 262208 '*' 512) -r -f /dev/sdb"
where 262208 was the start address assumed by "TestDisk".


> I will inquire to know if I can get that hardware repaired...

Given that my local food discounter sells 1 TiB USB3 hard disks for 55 EUR
i doubt that it is economically interesting to keep the drive in operation.


> All of this raises a number of questions concerning safe storage of data.

I am heavily biased towards having multiple backups on optical media.
Although they are not overly reliable at backup writing time, once
written and verified they survive a long time.


> usb ports have become faulty after 2-3 years

DVD or BD drives are easier to replace than USB ports, i assume. :))
One could see them as sacrificial hardware for the abrasive effects
of environment and time.

Normally my drives go blind before the tray servo breaks. Some last
since more than 10 years, others died after 20 months.
But the SATA or USB sockets where they were plugged had no problems
at all.


Have a nice day :)

Thomas

[toc] | [prev] | [next] | [standalone]


#189532 — Re: Need Help restoring a filesystem on an external drive WD 'My Book'

FromDavid Wright <deblis@lionunicorn.co.uk>
Date2017-12-04 02:00 +0100
SubjectRe: Need Help restoring a filesystem on an external drive WD 'My Book'
Message-ID<uSNh1-6kt-9@gated-at.bofh.it>
In reply to#189519
On Sun 03 Dec 2017 at 20:10:31 (+0100), Bernard wrote:

> All of this raises a number of questions concerning safe storage of
> data. What is available is far from reliable. Another problem is
> that of usb ports : on two of my three computers, usb ports have
> become faulty after 2-3 years ; on my old desktop dating back to
> 2007, on 5 usb ports, 3 are faulty ; when this started, I just had
> to sligntly move the plug into its slot, but this has ended in the
> fact that now each trial to plug anything in these slots causes an
> instant shutdown of the machine.

For desktops, you can buy USB ports. I have a couple of 3-port ones
myself, bought to save the hassle of plugging things into the mobo's
ones at the back of the cabinet. They fit where a 3½ floppy would go
but there are adapters to fit a 5¼ window as well. Each has two more
ports on the card itself.

Cheers,
David.

[toc] | [prev] | [next] | [standalone]


#189297

From"Thomas Schmitt" <scdbackup@gmx.net>
Date2017-11-26 11:50 +0100
Message-ID<uQ2Fz-6xI-3@gated-at.bofh.it>
In reply to#189295
Hi,

bd wrote:
> My other similar drives mount on /dev/sdb1 or /dev/sr0...

Well, sr0 is supposed to be an optical drive: CD, DVD, BD.

sdb1 is the first partition on harddisk-like drive sdb: spinning disk,
SSD disk, USB stick, ...


> If I list my /dev directory using ls -lt, I can see what new device appears
> in the list whenever I plug my external drive. It shows 'sdb'. Not 'sdb1' as
> for other external drives, just 'sdb'.

So it looks like the partition table on the drive is unreadable or was
overwritten by data which the Linux kernel interprets as empty partition
table or as no partition table.

Do you see messages about read errors in the output of dmesg ?

----------------------------------------------------------------------------

Depending on the general readability of the device and/or on the blocks
which have been altered, it could be possible to find the filesystem start,
mount it by a loop device, or create a new partition table which lets
/dev/sd1 mark the area of the filesystem.

The main task would be to guess the start of the partition. Its end is of
less importance because one could as a make-shift set it to the end of the
device.

Looking for the signature of ext3, i read in
  https://superuser.com/questions/239088/whats-a-file-systems-magic-number-in-a-super-block
  "an ext2/ext3/ext4 filesystem always has the bytes 0x53 0xEF at positions
   1080–1081"

which is confirmed by
  http://www.nongnu.org/ext2-doc/ext2.html
  "The superblock is always located at byte offset 1024 from the beginning of
   the file, block device or partition formatted with Ext2 and later variants
   (Ext3, Ext4).
   [...]
   Table 3-3. Superblock Structure
   Offset (bytes)  Size (bytes)    Description
   56               2              s_magic
   [...]
   3.1.16. s_magic
   16bit value identifying the file system as Ext2. The value is currently
   fixed to EXT2_SUPER_MAGIC of value 0xEF53."

So one would look for bytes 0x53 0xEF at byte offset 1080 from the start
of a full block. Maybe 512-byte-block 63 is a good first guess and block 2048
the next best one. In worst case a little program would have to test a few
thousand blocks before finding a candidate for the partition start.

As soon as you have a good candidate block address, you may use a loop
device on /dev/sdb with byte offset to mount it read-only without the need
for writing a new partition table to the drive.
(See man 8 losetup, option -o.)

In case of mount success you should make a thorough backup of the filesystem
content before performing any write operation on the drive.
Only with a good backup you should then consider to try repairing the
situation.


Have a nice day :)

Thomas

[toc] | [prev] | [next] | [standalone]


#189320 — Re: Need Help restoring a filesystem on an external drive WD 'My Book'

From"Alexander V. Makartsev" <avbetev@gmail.com>
Date2017-11-26 21:10 +0100
SubjectRe: Need Help restoring a filesystem on an external drive WD 'My Book'
Message-ID<uQbpv-42R-3@gated-at.bofh.it>
In reply to#189295

[Multipart message — attachments visible in raw view] — view raw

On 26.11.2017 14:37, bd wrote:
>
> Hi to Everyone,
>
> My
>
> WD P/N : WD10000H 1Q
>
> S/N : WCAU4D 164675
>
> is about 4 or 5 years old. It is an external drive using external
> power supply. At start, I had formatted it in ext3, so that I 'd be
> able to storage videofiles larger than 2 Gb. Since then, I storaged a
> number of files in several directories, subdirectories etc.. I never
> had any problem until now.
>
> This drive no longer mounts. It does not mount automatically as it
> used to, and I don't know how to mount it manually. My other similar
> drives mount on /dev/sdb1 or /dev/sr0... depending on to which
> computer I mount it. In case it doesn't automatically mount, I just type :
>
> #mount /dev/sdb1 /media/bd/ext
>
> and it works
>
> but right now I don't know for sure the device name to mount.
>
> If I list my /dev directory using ls -lt, I can see what new device
> appears in the list whenever I plug my external drive. It shows 'sdb'.
> Not 'sdb1' as for other external drives, just 'sdb'. If now I type :
>
> # mount /dev/sdb /media/bd/ext
>
> this gets the external drive to react : the light goes up and down for
> awhile, and then I get this message :
>
> 'you must specify the filesystem'
>
> But, if I try :
>
> # mount -t ext3 /dev/sdb /media/bd/ext
>
> I get this : 'wrong fs type, bad option, bad superblock on /dev/sdb…'
>
> same result if I try mounting on 'fat', 'msdos'… filesystems, but I
> doubt if there are any FAT or msdos space left on this device since I
> had reformated it to ext3.
>
> At last, I tried :
>
> # fsck /dev/sdb (the external drive starts to light, then :
>
> 'fsck ext2 : superblock invalid. Trying to backup blocks
>
> fsck ext2 : bad magic number in superblock while trying to open /dev/sdb
>
> Now, if I type :
>
> cat /proc/scsi/scsi
>
> I get this :
>
> scsi0 ATA MAXTOR STM
>
> scsi1 ATA MAXTOR STM
>
> scsi5 WD My Book Direct Access
>
>
> /etc/fstab
>
> does not show any sdb device
>
> How am I to get this drive back to operation, or, at least, to
> recuperate the datafiles that are stored in that WD external drive ?
>
> Thanks in advance to tell me what diagnosis and repair tools I could use
>
> Bernard
>
You have to specify partition to mount not whole disk device.
First of all check if you got disk name right (they could mix up on boot
time):
    # blkid
After that, right mount command should be like this:
    # mount -t ext3 /dev/sdb1 /media/bd/ext
If you suspect disk could be failing, you can mount it as read-only, to
see if it will mount cleanly:
    # mount -t ext3 -o ro /dev/sdb1 /media/bd/ext
To check unmounted ext3 filesystem of partition 1 you should type:
    # fsck.ext3 /dev/sdb1

-- 
With kindest regards, Alexander.

⢀⣴⠾⠻⢶⣦⠀ 
⣾⠁⢠⠒⠀⣿⡁ Debian - The universal operating system
⢿⡄⠘⠷⠚⠋⠀ https://www.debian.org
⠈⠳⣄⠀⠀⠀⠀ 

[toc] | [prev] | [next] | [standalone]


#189324 — Re: Need Help restoring a filesystem on an external drive WD 'My Book'

FromDavid Christensen <dpchrist@holgerdanske.com>
Date2017-11-26 22:40 +0100
SubjectRe: Need Help restoring a filesystem on an external drive WD 'My Book'
Message-ID<uQcOB-4PK-9@gated-at.bofh.it>
In reply to#189295
On 11/26/17 01:37, bd wrote:
> WD P/N : WD10000H 1Q
> 
> S/N : WCAU4D 164675
> 
> is about 4 or 5 years old. It is an external drive using external power 
> supply. At start, I had formatted it in ext3, so that I 'd be able to 
> storage videofiles larger than 2 Gb. Since then, I storaged a number of 
> files in several directories, subdirectories etc.. I never had any 
> problem until now.
> 
> This drive no longer mounts. 

Were there any events immediately prior to this change -- power outage, 
dropped the external drive, updated software, installed software, 
changed system configuration settings, etc.?


> It does not mount automatically as it used 
> to, and I don't know how to mount it manually. My other similar drives 
> mount on /dev/sdb1 or /dev/sr0... depending on to which computer I mount 
> it. In case it doesn't automatically mount, I just type :
> 
> #mount /dev/sdb1 /media/bd/ext
> 
> and it works

That incantation might work, if the external drive is assigned to 
/dev/sdb by the kernel, the HDD has a partition table, the ext3 file 
system is in the first partition, and the directory /media/bd/ext 
exists.  But, the /media directory is usually managed by automount 
software, so messing with it could cause problems.  I typically put my 
mount points under /mnt.


> but right now I don't know for sure the device name to mount.
> 
> If I list my /dev directory using ls -lt, I can see what new device 
> appears in the list whenever I plug my external drive. It shows 'sdb'. 
> Not 'sdb1' as for other external drives, just 'sdb'. If now I type :
> 
> # mount /dev/sdb /media/bd/ext

That would be correct only if you put the ext3 file system directly on 
the raw drive without a partition table.  As you stated it used to mount 
automatically, that implies a partition table.  Therefore, this 
incantation is likely wrong.


> this gets the external drive to react : the light goes up and down for 
> awhile, and then I get this message :
> 
> 'you must specify the filesystem'
> 
> But, if I try :
> 
> # mount -t ext3 /dev/sdb /media/bd/ext
> 
> I get this : 'wrong fs type, bad option, bad superblock on /dev/sdb…'

Also, likely a wrong incantation.


> same result if I try mounting on 'fat', 'msdos'… filesystems, but I 
> doubt if there are any FAT or msdos space left on this device since I 
> had reformated it to ext3.
> 
> At last, I tried :
> 
> # fsck /dev/sdb (the external drive starts to light, then :
> 
> 'fsck ext2 : superblock invalid. Trying to backup blocks
> 
> fsck ext2 : bad magic number in superblock while trying to open /dev/sdb

Also, likely a wrong incantation; and dangerous.  Hopefully, fsck(8) 
didn't overwrite any bits on disk.


> Now, if I type :
> 
> cat /proc/scsi/scsi
> 
> I get this :
> 
> scsi0 ATA MAXTOR STM
> 
> scsi1 ATA MAXTOR STM
> 
> scsi5 WD My Book Direct Access

So, the kernel can see the drive at least part of the time.


> /etc/fstab
> 
> does not show any sdb device

/etc/fstab typically contains entries created by the installer and by 
the system administrator (you).  Automatic mounting should not modify 
this file.


> How am I to get this drive back to operation, or, at least, to 
> recuperate the datafiles that are stored in that WD external drive ?
> 
> Thanks in advance to tell me what diagnosis and repair tools I could use

All the software in the world won't help you if the hardware is failing 
-- the external power supply could be bad, the electronics in the 
plastic box could be bad, or the drive could be bad.  I've seen all three.


Download and run WD's Data Lifeguard Diagnostic to verify the external 
drive:

    https://support.wdc.com/downloads.aspx


Reply with the results.


David

[toc] | [prev] | [next] | [standalone]


#189328 — Re: Need Help restoring a filesystem on an external drive WD 'My Book'

FromRichard Hector <richard@walnut.gen.nz>
Date2017-11-27 03:10 +0100
SubjectRe: Need Help restoring a filesystem on an external drive WD 'My Book'
Message-ID<uQh1U-7Bb-3@gated-at.bofh.it>
In reply to#189295

[Multipart message — attachments visible in raw view] — view raw

On 26/11/17 22:37, bd wrote:
> This drive no longer mounts

FWIW, my WD external drive stopped mounting. I opened the case (with
difficulty, and possibly breakage, IIRC) removed the drive, and used it
as a normal SATA drive. Still working fine, all the data was there.

This may be completely unrelated to your issue ...

Richard

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web