• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

API for low-level drive access

280Z28

n00b
Joined
May 5, 2006
Messages
58
I need programmatic direct read access to bytes on a drive surface at an absolute offset with no consideration of the file system or partitions. What functions in the Windows API are responsible for this?


Fine print (here's why I need it):

I sent this message to Promise Inc. regarding drives on a FastTrax SX4000:

I had a drive fail (bad blocks encountered) during an online array expansion from a 3-drive RAID-0 to a 4-drive RAID-5. I need a way to find out which parts of the drives were converted to RAID-5 and which parts are still RAID-0 based on the binary promise block found at the end of the disk. With this information, I can create spans of RAID-0/5 inside my recovery program and splice them together to form what would have been the online drive image. At that point, everything should be recoverable that lied outside the bad block. Since the 600gb drive had only 150GB of data, and the bad section is only a couple GB at most, most or all of the data should be fine.

For what it's worth, the array conversion stopped itself at the 66% complete mark and stayed that way for over 12 hours giving messages in the Windows event log about encountering drive errors and having to reset the channels.

My failed drive's warranty expires in less than 1 week, so it's important I know this information ASAP so I can try to get my data back.

As a last resort I plan to start at the beginning and end of the disk and test which parts of the drive have matching parity information to make a best guess of which parts were converted. I can then make my virtual disk spans meet in the middle based on the results.
 
mikeblas said:
CreateFile() to open the device and SetFilePointer() and ReadFile() to do the reading against the device handle.

You'll want to read the section about "Physical Disks and Volumes" to understand what string to give CreateFile() to open either logical volume or the physical disk unit.

GetVolumeInformation() can tell you about the drive geometry.

Thank you, I saw GetVolumeInformation but CreateFile didn't look like what I wanted to do (by the name) so I never looked at the docs for it. :eek:
 
The scan was easier than I thought. Binary search FTW! My program calculated the parity of the 5 sector block starting with the sector I entered, and I kept track in Notepad.

Code:
300000000 X
281250000 X
271875000 X
267187500 X
264843750 X
263671875 X
263085937 X
262792968 X
262646484 X
262609863 X
262605285 X
262604998 X
262604927 X
262604855 +
262604712 +
262604140 +
262602996 +
262600707 +
262591552 +
262573242 +
262500000 +
225000000 +
150000000 +

Bringing me down to this in about 10 minutes. It's the XOR of all 4 drives, so straight zeros indicates a parity match:

Code:
Sector 262604926:

00000200  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
00000210  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
00000220  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
00000230  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
00000240  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
00000250  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
00000260  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
00000270  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
00000280  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
00000290  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
000002A0  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
000002B0  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
000002C0  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
000002D0  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
000002E0  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
000002F0  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
00000300  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
00000310  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
00000320  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
00000330  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
00000340  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
00000350  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
00000360  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
00000370  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
00000380  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
00000390  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
000003A0  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
000003B0  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
000003C0  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
000003D0  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
000003E0  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
000003F0  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00

Sector 262604927:

00000400  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
00000410  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
00000420  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
00000430  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
00000440  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
00000450  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
00000460  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
00000470  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
00000480  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
00000490  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
000004A0  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
000004B0  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
000004C0  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
000004D0  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
000004E0  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
000004F0  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
00000500  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
00000510  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
00000520  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
00000530  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
00000540  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
00000550  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
00000560  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
00000570  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
00000580  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
00000590  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
000005A0  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
000005B0  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
000005C0  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
000005D0  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
000005E0  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00
000005F0  00 00 00 00 00 00 00 00   00 00 00 00 00 00 00 00

Sector 262604928:

00000600  C6 0A 43 AD FA 19 E7 65   BE 1F 9F 1E B6 32 C5 20
00000610  A7 E7 D0 EE 9B 08 4C 7E   A8 68 EC 09 56 4F A1 94
00000620  F1 FD BA 12 DD BA ED 2E   8E 87 B2 60 FF 28 A0 8F
00000630  61 04 FF 8F BC 93 18 AE   62 ED AB 9A 65 6A 47 5B
00000640  64 BF C6 95 9D BF BB BF   6B 94 63 81 CE 1A F8 A9
00000650  EF 3D 30 EE A6 34 2E 6A   75 94 DB 1E 57 1E 7F A1
00000660  FE A7 D5 7D EA 25 46 9D   43 D8 77 35 9A B2 74 73
00000670  81 83 BA 13 63 09 0F 4B   EB E8 EC BA F1 B2 ED F0
00000680  68 C4 4C F0 10 63 AB D5   4F CC E7 37 73 DE D7 48
00000690  26 B3 22 D6 52 6D DE 83   7A DA DB 7D BF 49 24 E2
000006A0  0D 8B 62 54 27 17 09 BE   2B 71 2A F3 0F 52 00 31
000006B0  CD F2 ED BA 10 62 56 A4   A2 B9 3F C5 3B AA CA 82
000006C0  B6 E8 0B FB 1C 79 65 EA   42 7A C7 3C 5E 29 01 27
000006D0  B5 B0 AA 6E E2 E9 BF 06   05 58 62 E5 B0 5B 00 48
000006E0  79 67 6D 15 CF 46 9C 8D   0A 8A A5 D4 18 EC 16 79
000006F0  AC 2C 92 60 ED 34 5F 11   DB 80 45 DA DE A4 93 95
00000700  A0 4D 50 E7 1F F6 B8 25   52 18 A0 83 BA 36 F4 F4
00000710  0F D4 EF 60 39 F6 88 14   EB 72 6E FA 05 C4 18 47
00000720  79 A8 1F 52 88 67 1F 93   02 54 13 AF 18 7E DE C9
00000730  D3 9D EC CB 86 19 F3 DD   02 9C B3 AB 39 E7 CB 4F
00000740  6C 4D 8E CF FA E2 63 99   39 97 61 91 F5 E8 81 6C
00000750  D2 A4 4F 3A ED 08 A9 A8   17 62 2C 12 EF E4 2E 37
00000760  AC 3E EB AB 25 48 4C 41   31 C9 1E D4 FC 5A D2 26
00000770  12 48 F9 06 3A E7 A9 FA   8B AE 8C 0C 22 D1 1D AF
00000780  F0 4E 55 2B A4 9B 4B 5C   6E 40 06 67 5D 2B 1E 10
00000790  C7 A7 3C 4E 09 10 07 B5   70 B8 7C D3 D0 D6 AF 9F
000007A0  60 16 A1 55 3D 06 5D 2E   25 AC 63 14 21 DA EA 3C
000007B0  32 C4 99 F8 8F E4 90 62   1C A7 4C F0 0C A6 6D 28
000007C0  7F 7C 26 89 ED 4A 93 C7   31 8C 86 92 81 3D D8 38
000007D0  D5 F1 B5 C7 38 A7 B4 3F   3C CC FD 96 E6 14 F6 A8
000007E0  EB EB 8B 60 71 CA FE 65   C8 70 81 1F 35 D2 AF BE
000007F0  49 B1 FB 0E 54 B9 D4 70   69 49 9A 2A 65 F4 21 6E

Sector 262604929:

00000800  A8 B5 B7 03 BA F6 68 9C   C7 45 27 B5 CF 35 60 5D
00000810  CB 64 3B BD DC 84 01 89   5A 34 ED D5 3E 0B C9 67
00000820  9E E0 74 5C D5 02 00 7F   5B B3 B4 6B 42 26 6D 2B
00000830  BE 2B 26 45 D5 E4 B4 E3   CA 67 A5 3D B1 50 4C 04
00000840  08 C9 B9 1C C9 17 C2 4C   6B 78 F8 45 67 3F BF B5
00000850  F8 DB B2 67 96 BA D0 88   9B 21 4C F2 62 19 9B 83
00000860  F7 F2 44 C7 D0 7D 64 C5   83 20 26 06 51 7E 41 03
00000870  E7 BA EB 61 86 23 06 1C   BA 95 CE 07 9F 95 27 D5
00000880  77 92 17 C5 DB CC B5 57   F8 CE BD 3D 1F AB AB 65
00000890  A8 7D AD 40 92 DB B9 30   44 01 48 1D 4E 14 A5 24
000008A0  05 4E B3 4A 94 5F BD B0   8A 46 ED 4B 27 B0 90 08
000008B0  57 09 55 EE E3 65 FE 46   01 49 8B 13 9B EA F8 BE
000008C0  5C 66 5E 94 0F 0B 50 60   9E F7 BA 6F 84 E5 67 A6
000008D0  A1 47 4D 30 1F 55 FC 50   A1 00 A1 D7 36 03 D2 E7
000008E0  6F A7 2C E2 70 BF 3C A0   3E 24 B3 8C AB 95 FD B5
000008F0  73 B5 02 5D 26 19 1B 7D   9B 79 77 3C 4D 25 70 E2
00000900  3E 57 1E 41 51 9C 57 23   A6 89 D6 59 64 DF CA DC
00000910  E6 05 64 E7 43 48 09 75   00 81 7C 9C B6 F0 86 D7
00000920  AC 99 79 34 87 8B 85 C6   0B D0 CD DF F1 1F DE A5
00000930  E9 45 E1 06 9A FF E6 58   67 D3 F7 FD 45 D2 C9 E0
00000940  DC DF 15 A8 27 6F 54 54   11 D5 48 7D 17 67 A7 91
00000950  BA BA 64 5F CB 7B 6B D9   29 98 71 50 E7 C3 B9 C6
00000960  A9 AB FA 28 14 7D 55 90   00 85 E6 3D 0D 94 07 AC
00000970  2D 0B 04 1D F1 E1 8C 3B   73 FB 31 8C 06 2A 7C 56
00000980  50 07 A3 59 6A E0 A6 62   ED 37 EA BE F9 13 0D 79
00000990  81 79 40 6A 4E DF BE A1   BD 3D 0B 1F 16 05 01 1F
000009A0  43 BB 69 92 B1 D7 BC F5   35 79 27 8A C6 4D 7C D6
000009B0  38 81 AB AD 9E 02 FE 2C   24 5A F2 89 C7 40 D7 67
000009C0  E6 EB A7 A5 1B 73 18 86   A5 FA CC 90 FD 58 5A FB
000009D0  A5 57 49 5D 34 10 3E FB   0A DA F0 3A 90 02 2E 96
000009E0  17 2E A4 21 EF CA C2 3B   89 5A 23 9C F8 82 5C 87
000009F0  DB 01 74 66 B7 D6 20 66   9C EE CC DA 40 06 10 97
 
I hand matched the parity and aligned the stripe set and recovered **everything** :cool: :eek: :eek: :D
 
that just went way over my head . but I liked it :D gj on the recovery
 
How'd you go from knowing the location of the raid 0/5 areas to having the ability to actually recover the data? ie, how'd this become actionable? What was the recovery program you used.

Would you post the source code to your program? I understand that it probably lacks any polish, but I'm rather curious to see it. I like low level programming.
 
kleptophobiac said:
How'd you go from knowing the location of the raid 0/5 areas to having the ability to actually recover the data? ie, how'd this become actionable? What was the recovery program you used.

Would you post the source code to your program? I understand that it probably lacks any polish, but I'm rather curious to see it. I like low level programming.

I'll post the code here, which I didn't change or clean up at all from what I actually used. Also, better explanation of what I did from beginning to end:

http://www.hardforum.com/showthread.php?t=1066458
 
Back
Top