How 7-Zip Inspects FAT32 and NTFS Boot Sectors
7-Zip can parse and extract files directly from raw disk images, such
as .img, .dd, or uncompressed virtual disk
formats, without requiring administrative privileges or mounting the
image through the operating system. It achieves this by acting as a
stream-level file system parser. By scanning the disk image for
partition tables and reading the partition boot records—specifically the
BIOS Parameter Block (BPB) for FAT32 and NTFS—7-Zip interprets the
geometry and file tables of the raw data directly within its internal
archive handlers.
Partition Detection and Offset Calculation
When opening a raw disk dump, 7-Zip first determines whether the file represents an entire partitioned disk or a standalone partition.
- Full Disk Images (MBR/GPT): 7-Zip checks sector 0
(LBA 0) for Master Boot Record (MBR) structures, verifying the
0x55AAsignature at offset0x1FEand evaluating the partition table entries starting at offset0x1BE. For GUID Partition Tables (GPT), it reads LBA 1 to find the"EFI PART"signature and parse the partition arrays. Once a partition is identified, 7-Zip calculates the starting byte offset of that partition within the raw dump. - Raw Partition Dumps: If the image is a direct dump
of a single volume rather than an entire drive, the boot sector sits
directly at byte offset
0.
Once the partition offset is established, 7-Zip routes the stream to
the appropriate format handler: NtsfHandler for NTFS or
FatHandler for FAT/FAT32.
Parsing the NTFS Boot Sector
To read an NTFS partition, 7-Zip examines the Volume Boot Record (VBR) located at the first sector of the partition:
- Signature Verification: It checks byte offset
0x03for the 8-byte OEM identifier string"NTFS ". It also verifies the standard boot record end-of-sector marker0x55AAat offset0x1FE. - Geometry Extraction: 7-Zip reads the BIOS Parameter
Block (BPB) to determine basic volume layout:
- Bytes per sector at offset
0x0B(typically 512 or 4096). - Sectors per cluster at offset
0x0D(determining the cluster size).
- Bytes per sector at offset
- **Locating the Master File Table (\(MFT):** The critical step occurs at offset `0x30`, where the starting cluster number of the Master File Table (\)MFT) is stored as a 64-bit integer. 7-Zip multiplies this cluster number by the sectors-per-cluster and bytes-per-sector values, adding the partition's starting offset.
- **Reading \(MFT Records:** Using this
calculated byte address, 7-Zip reads record 0 of the
`\)MFT
, parses its standard 1024-byte record structure, evaluates theFILEmagic bytes, and tracks the$DATA` attribute runs to map out the entire file system hierarchy.
Parsing the FAT32 Boot Sector
For FAT32 partitions, 7-Zip inspects the extended BPB within the volume boot record:
- Signature Verification: 7-Zip looks for the
standard jump instructions at offset
0x00(0xEBor0xE9), checks for the file system string"FAT32 "at offset0x52, and validates the0x55AAsignature at offset0x1FE. - Geometry and Reserved Space: It extracts
fundamental layout values:
- Bytes per sector at offset
0x0B. - Sectors per cluster at offset
0x0D. - Reserved sector count at offset
0x0E. This dictates the exact offset where the File Allocation Tables (FAT) begin. - Number of FATs at offset
0x10(typically 2).
- Bytes per sector at offset
- Extended BPB Fields:
- Sectors per FAT at offset
0x24(a 32-bit value defining the size of each FAT). - Root Directory starting cluster at offset
0x2C(typically cluster 2).
- Sectors per FAT at offset
- Data Region Mapping: 7-Zip calculates the start of
the data region using the formula: \[\text{Data Start Offset} = (\text{Reserved
Sectors} + (\text{Number of FATs} \times \text{Sectors Per FAT})) \times
\text{Bytes Per Sector}\] With the data start offset and the root
directory cluster known, 7-Zip follows the cluster chains in the FAT
table to read directory entries (
0x20-byte structures) and reconstruct the directory tree for browsing and extraction.