unprotected-CHFI v3 Module 09 Windows Linux Macintosh.pdf

(1419 KB) Pobierz
Computer Hacking
Forensic Investigator
g
Module IX
Windows, Linux and
Macintosh Boot Process
Module Objective
This module will familiarize you with the following:
Terminology
Boot loaders
Boot sectors
Basic system b
i
boot process
MSDOS boot process
Windows XP boot process
Linux boot process
Macintosh boot process
EC-Council
Copyright © by
EC-Council
All Rights Reserved. Reproduction is Strictly Prohibited
Module Flow
Terminologies
T
i l i
Boot Loader
B
L d
Basic System Boot Process
Boot Sector
DOS boot process
Windows XP boot process
Mac boot process
Linux boot process
EC-Council
Copyright © by
EC-Council
All Rights Reserved. Reproduction is Strictly Prohibited
Terminologies
Booting
Booting is a process that starts operating systems when the user turns on a computer system.
Bootstrap may be defined as a simple program that actually begins the initialization of the
computer's operating system.
Basic Input/Output System or Basic Integrated Operating System
System.
Performs booting process.
Complementary metal oxide semiconductor (CMOS) is a widely used type of semiconductor.
Computers contain a small amount of battery powered CMOS memory to hold the date time and
battery-powered
date, time,
system setup parameters.
It is the set of operations the computer performs when it is switched on that load an operating
system.
Starting computer from a powered-down, or off, state.
Restarting computer that is already turned on via the operating system
system.
Bootstrap
BIOS
CMOS
Boot Sequence
Cold boot (Hard boot)
Warm boot (Soft boot)
EC-Council
Copyright © by
EC-Council
All Rights Reserved. Reproduction is Strictly Prohibited
Boot Loader
It is a small program that loads the operating system into the computer’s memory when
the system i b
h
is booted.
d
A basic bootloader has following
eight instructions:
0: set the P register to 8.
1: check paper tape reader
ready.
2: if not ready, jump to 1.
3: read a byte from paper tape
reader to accumulator.
accumulator
4: if end of tape, jump to 8.
5: store accumulator to address
in P register.
6: increment th P register.
6 i
t the
i t
7: jump to 1.
EC-Council
Copyright © by
EC-Council
All Rights Reserved. Reproduction is Strictly Prohibited
Zgłoś jeśli naruszono regulamin