Showing posts with label IPhone. Show all posts
Showing posts with label IPhone. Show all posts

Sunday, October 29, 2017

Threema - white paper

Latest white paper Sept 2017

https://threema.ch/press-files/2_documentation/cryptography_whitepaper.pdf

Threema-iTunes
 
Threema is the world’s favourite secure messenger and keeps your data out of the hands of hackers, corporations and governments. Threema can be used completely anonymously, allows to make end-to-end encrypted voice calls, and offers every feature one would expect from a state-of-the-art instant messenger.

Useful for running lab tests.
https://itunes.apple.com/gb/app/threema/id578665578?mt=8

Wednesday, June 14, 2017

iPhone - TDEL034 Tool Testing


Many discussions take place during training which unearth useful guidance for practices and procedures. Also, tips and tricks are also revealed. From the MTEB Tool Testing training papers 2015 - iPhone TDEL034 (test device entry level) strategies and pre-planning - it is used to illustrate potential stages for obtaining images that produce a baseline test data to enable repeated testing to identify possible changes in the working operation of forensic tool suites importing a pre-existing test image.

However, TDEL034 is, as stated above, for strategies and pre-planning. Acquisition tools and Analysis (reader/reveal) tools are dealt with later in the training. What is uncovered during discussions are peoples perceptions given their involvement within the examination process. 

It is in these sessions during training the reality dawns as to the time and expense it takes just to deal with one brand-name 'Make' of smartphone and then adding into the equation the various models that have been created and may be created in the future. If that isn't enough, there is then the various versions of OS implemented in various models (https://en.wikipedia.org/wiki/IOS_version_history).

The discovery doesn't end there. Tasks involving removal of barriers and revelation equally may impact when discussing discovery (https://en.wikipedia.org/wiki/IOS_jailbreaking).

Digital forensics is a reality and not a junk science. This field of endeavour is unlike traditional sciences incl. many forensic sciences. How many traditional sciences can you identify evolve and update rapidly e.g. every 6mths-12mths? It is against this backdrop that digital forensics is expected to function and operate across a digital arena of many makes/models of devices and services. Understanding the fantastic job that people do working in digital forensics and battling with constant change illustrates how digital forensics is highly unique.

Generic standards do not work as well with digital forensics as would 'specific' standards. That is because with generic standards they are tantamount to informing everyone this is what has been created and it is your responsibility to make it work. This is analogous to an organisation purchasing a SATNAV and Driving Route System which when operational fails to inform the driver of 'No Entry' roads, dead end roads, instructing a driver to take the action even when the sign states 'No Left Turn' or using as-the-crow-flies navigation so the driver is placed at a point e.g. x-miles from true destination, because the system doesn't understand vehicles cannot drive through people houses, gardens or buildings to get to the other side. The organisation then expects the driver to workout the problems so that when reaching the destination it looks like the SATNAV and Driving Route System was working correctly.

This is why training is essential not just at the tool level, but also at the conceptual level to assist in the design of an examination approach that fits the need of the device and at the same time relieve the pressure placed on the tools that are expected to, alone, get it right. Having the right digital forensic standard should provide the baseline and should define process approach to assist achieve results.

I will return to this subject to offer observations a little later, but for now other matters are now pressing and need attention.

Saturday, April 01, 2017

Monolith Recovery


Wow! The future of handling chip off exploration looks great with this new innovation tool to get at content in Flash memory microchips:

UFD (USB Flash Drive)
SD (Secure Digital Card)
CF (Compact Flash)
micro SD (micro Secure Digital Card)
MS (Memory Stick)
xD
Monolithic Flash Devices
MMC (Multi Media Card)
eMMC (embedded Multi Media Card)
VoiceRecorder (dictaphone)
iPhone (without hardware encryption)

Friday, September 02, 2016

Apple iPhone connected devices

Proliferation of mobile devices and computers associated with cybercrimes and legal disputes grow on a daily basis. I thought perhaps readers might find this 2015 document a useful and helpful reminder. DEFT Practice Notice J10702015.pdf
 

Sunday, March 16, 2014

Test your USIM knowledge

Below is UST (USIM Service Table) 3GPP 31.102 that may be found in a UST elementary file.

QUESTION 1
There are at minimum 1,900 items for examination discovery, investigatory leads and evidence that can be obtained from these UST entries.  Can you identify just 50 items for examination discovery, investigatory leads and evidence? If so, what are they?

Service n°1: Local Phone Book
Service n°2: Fixed Dialling Numbers (FDN)
Service n°3: Extension 2
Service n°4: Service Dialling Numbers (SDN)
Service n°5: Extension3
Service n°6: Barred Dialling Numbers (BDN)
Service n°7: Extension4
Service n°8: Outgoing Call Information (OCI and OCT)
Service n°9: Incoming Call Information (ICI and ICT)
Service n°10: Short Message Storage (SMS)
Service n°11: Short Message Status Reports (SMSR)
Service n°12: Short Message Service Parameters (SMSP)
Service n°13: Advice of Charge (AoC)
Service n°14: Capability Configuration Parameters 2 (CCP2)
Service n°15: Cell Broadcast Message Identifier
Service n°16: Cell Broadcast Message Identifier Ranges
Service n°17: Group Identifier Level 1
Service n°18: Group Identifier Level 2
Service n°19: Service Provider Name
Service n°20: User controlled PLMN selector with Access Technology
Service n°21: MSISDN
Service n°22: Image (IMG)
Service n°23: Support of Localised Service Areas (SoLSA)
Service n°24: Enhanced Multi Level Precedence and Pre emption Service
Service n°25: Automatic Answer for eMLPP
Service n°26: RFU
Service n°27: GSM Access
Service n°28: Data download via SMS-PP
Service n°29: Data download via SMS CB
Service n°30: Call Control by USIM
Service n°31: MO-SMS Control by USIM
Service n°32: RUN AT COMMAND command
Service n°33: shall be set to '1'
Service n°34: Enabled Services Table
Service n°35: APN Control List (ACL)
Service n°36: Depersonalisation Control Keys
Service n°37: Co-operative Network List
Service n°38: GSM security context
Service n°39: CPBCCH Information
Service n°40: Investigation Scan
Service n°41: MexE
Service n°42: Operator controlled PLMN selector with Access Technology
Service n°43: HPLMN selector with Access Technology
Service n°44: Extension 5
Service n°45: PLMN Network Name
Service n°46: Operator PLMN List
Service n°47: Mailbox Dialling Numbers
Service n°48: Message Waiting Indication Status
Service n°49: Call Forwarding Indication Status
Service n°50: Reserved and shall be ignored
Service n°51: Service Provider Display Information
Service n°52 Multimedia Messaging Service (MMS)
Service n°53 Extension 8
Service n°54 Call control on GPRS by USIM
Service n°55 MMS User Connectivity Parameters
Service n°56 Network's indication of alerting in the MS (NIA)
Service n°57 VGCS Group Identifier List (EFVGCS and EFVGCSS)
Service n°58 VBS Group Identifier List (EFVBS and EFVBSS)
Service n°59 Pseudonym
Service n°60 User Controlled PLMN selector for I-WLAN access
Service n°61 Operator Controlled PLMN selector for I-WLAN access
Service n°62 User controlled WSID list
Service n°63 Operator controlled WSID list
Service n°64 VGCS security
Service n°65 VBS security
Service n°66 WLAN Reauthentication Identity
Service n°67 Multimedia Messages Storage
Service n°68 Generic Bootstrapping Architecture (GBA)
Service n°69 MBMS security
Service n°70 Data download via USSD and USSD application mode
Service n°71 Equivalent HPLMN
Service n°72 Additional TERMINAL PROFILE after UICC activation
Service n°73 Equivalent HPLMN Presentation Indication
Service n°74 Last RPLMN Selection Indication
Service n°75 OMA BCAST Smart Card Profile
Service n°76 GBA-based Local Key Establishment Mechanism
Service n°77 Terminal Applications
Service n°78 Service Provider Name Icon
Service n°79 PLMN Network Name Icon
Service n°80 Connectivity Parameters for USIM IP connections
Service n°81 Home I-WLAN Specific Identifier List
Service n°82 I-WLAN Equivalent HPLMN Presentation Indication
Service n°83 I-WLAN HPLMN Priority Indication
Service n°84 I-WLAN Last Registered PLMN
Service n°85 EPS Mobility Management Information
Service n°86 Allowed CSG Lists and corresponding indications
Service n°87 Call control on EPS PDN connection by USIM
Service n°88 HPLMN Direct Access
Service n°89 eCall Data
Service n°90 Operator CSG Lists and corresponding indications
Service n°91 Support for SM-over-IP
Service n°92 Support of CSG Display Control
Service n°93 Communication Control for IMS by USIM
Service n°94 Extended Terminal Applications
Service n°95 Support of UICC access to IMS
Service n°96 Non-Access Stratum configuration by USIM
Service n°97 PWS configuration by USIM 


QUESTION 2
An officer approaches you as the expert to investigate comminucations on an iPhone. There is known comms that have taken place but the twist is the comms at the distance end are being received by a Satellite phone. The user of the SatPhone is known to be trafficking in young children snatched from parents whilst on holiday. Your job is to provide evidence to help the police officer regarding which elementary files in the USIM would be used to permit mobile network usage (home and roaming) and any network artefacts that maybe connected to Satellite comms? To help you, a link below leads you to a piece of equipment that links iPhone to satellite:

www.thuraya.com/

Sunday, April 21, 2013

iPhone to Android

iPhone to Android

Interesting tool:

1 Transfer iPhone SMS and MMS with attachments to Android
2 Transfer SMS and MMS to Android from iTunes Backup
3 Extract picture, video, audio attachments from iPhone MMS to computer
4 Save iPhone SMS and MMS to local database on computer
5 Copy SMS and MMS from PC local database to Android
6 Export iPhone SMS and MMS to document files
7 Print out iPhone SMS and MMS in amazing threading mode

http://www.backuptrans.com/iphone-sms-mms-to-android-transfer.html

Tuesday, December 11, 2012

A European Focused Mobile Consumer Survey

A European Focused Mobile Consumer Survey

Informa Telecom and Media have published the results of their Smartphone Usage and Behaviour Survey 2012 conducting the survey in four european countries UK, Spain, Germany and the Netherlands http://www.informatandm.com/mobile-consumer-survey/ .

The results for the UK identified the brand of mobile phone owned in particular age groups.













The responses to the survey confirm that the smartphone market in the UK is segmented and therefore mobile operators attempting to forecast device usage and data/services activity may require enabling customers the selection and choice of a range of platforms to sink their teeth into optimising any consumer initiative to enable the growth of smartphones to continue.

For examiners the survey illustrates that predominantly the smartphones to be examined fall into a fairly small category, which could be quite useful for forecasting future examinations and, in particular, the expenditure on tools etc.

Sunday, November 11, 2012

iPhone Secret Folder

iPhone Secret Folder

Opening the taps on this one could prove useful:


iPhone Screenshot 1

 iPhone Screenshot 2

https://itunes.apple.com/us/app/secrets-folder-pro-lock-your/id566516598?mt=8

Tuesday, October 30, 2012

A Hacker's Guide: iOS6 Kernel Security

A Hacker's Guide: iOS6 Kernel Security



The recent release of iOS6 has introduced improved security by strengthening the Kernel. This presentation demonstrates that, on the face of it, jailbreaking strategies appear to have been one of the prime targets. This could impact severely on data extraction and harvesting techniques and some of the reading devices out there used by examiners to gather and produce evidence.

Download here: A Hacker's Guide: iOS6 Kernel Security 

Updated 31/10/12
Having posted the link to the above Hacker's Guide presentation I thought, perhaps wrongly, but I thought it anyway, that maybe the forensic community might have something to say on the subject. Perhaps to illustrate conflicts or contradictions in the marketplace, such as:

(a) the findings of the authors in that presentation compared with manufacturers out there that confirm their readers do work with iOS6 e.g.

- Oxygen Forensic Software http://www.forensicfocus.com/News/article/sid=1951/?
- UFED, XRY http://www.forensicfocus.com/Forums/viewtopic/t=9717/?

(b) how many have actually examined an iOS6 device and which reader was most useful?

(c) with an ever growing list of hacker presentations that expose exploits, vulnerabilities etc how many of those are used by the current iOS reading tools to extract and harvest data?

or maybe

(d) whether the published hacker exploits and perceived issues do not impact on the examiner community or the hacker presentations have no value at all?

Saturday, July 28, 2012

Clueful knows what iPhone apps are doing



For those wishing to retain privacy or those involved in eDiscovery, investigation, examination and/or evidence Bitdefender's Clueful identifies deviant apps on an iPhone currently running in memory allowing user's to identifying what an apps is doing and read an audit report accessed at Clueful Cloud. The audit report identifies:
  • which apps can access your address book;
  • which apps gather analytics in order to monitor you;
  • which apps can track your location;
  • which apps can access your Facebook or Twitter credentials;
  • which apps display ads;
  • which apps drain your battery through their improper use of background services, such as GPS or audio services.
This is one of those tools which highlights why mobile/smart phone examination is not simply limited to physical and logical data extraction but places an emphasis on examiners/investigators having additional capability to possess a wide range of information beyond harvested data and provide interpretations about possible activities on a particular handset.

Faqs - http://www.cluefulapp.com/faq.html